next up previous contents
Next: Try not to flood Up: Options description Previous: Do not execute unprotected   Contents

Enable init children lock feature

Saying yes here will compile the necessary code for the feature. You can then activate the feature with lidsadm (+LOCK_INIT_CHILDREN) It will prevent anybody from killing processes whose parent is init and which are running when you issue the command. Future daemon won't be protected, you must reissue a lidsadm command with -LOCK_INIT_CHILDREN then with +LOCK_INIT_CHILDREN. This mean that no one could stop them (denial of service) or even reload them with a new configuration file (restart or kill -HUP).

Saying yes and using it increases security.



Biondi Philippe 2000-02-24