security/Bastille - The NetBSD Packages Collection

System hardening tool focusing on educating the user

Bastille is a system hardening / lockdown program which enhances the
security of a Unix host.  It configures daemons, system settings and
firewalls to be more secure.  It can shut off unneeded services like rcp
and rlogin, and helps create "chroot jails" that help limit the
vulnerability of common Internet services like Web services and DNS.

This tool currently hardens Red Hat (Fedora Core, Enterprise and
Legacy/Classic), SuSE, Debian, Gentoo, Mandrake Linux, HP-UX, Mac OS X
and Turbo Linux.

If run in the preferred interactive mode, it can teach you a good deal
about  security while personalizing your system security state.

Bastille can also assess and report on the state of a system, which may
serve as an aid to security administrators, auditors and system
administrators who wish to investigate the state of their system's
hardening without making changes to such.  This assessment functionality
has only been tested on Red Hat Linux (Fedora, Legacy, Enterprise) and
SUSE systems.

Build dependencies

sysutils/checkperms devel/glib2-tools pkgtools/mktools pkgtools/cwrappers

Runtime dependencies

x11/p5-Tk shells/bash lang/perl5 devel/GConf devel/GConf

Binary packages

OSArchitectureVersion
NetBSD 10.0aarch64Bastille-3.0.9nb13.tgz
NetBSD 10.0aarch64Bastille-3.0.9nb13.tgz
NetBSD 10.0aarch64ebBastille-3.0.9nb13.tgz
NetBSD 10.0aarch64ebBastille-3.0.9nb13.tgz
NetBSD 10.0alphaBastille-3.0.9nb12.tgz
NetBSD 10.0alphaBastille-3.0.9nb13.tgz
NetBSD 10.0alphaBastille-3.0.9nb13.tgz
NetBSD 10.0earmv6hfBastille-3.0.9nb13.tgz
NetBSD 10.0earmv6hfBastille-3.0.9nb12.tgz
NetBSD 10.0earmv6hfBastille-3.0.9nb13.tgz
NetBSD 10.0earmv7hfBastille-3.0.9nb13.tgz
NetBSD 10.0earmv7hfBastille-3.0.9nb12.tgz
NetBSD 10.0earmv7hfBastille-3.0.9nb13.tgz
NetBSD 10.0i386Bastille-3.0.9nb13.tgz
NetBSD 10.0i386Bastille-3.0.9nb13.tgz
NetBSD 10.0powerpcBastille-3.0.9nb11.tgz
NetBSD 10.0powerpcBastille-3.0.9nb12.tgz
NetBSD 10.0powerpcBastille-3.0.9nb12.tgz
NetBSD 10.0sparc64Bastille-3.0.9nb13.tgz
NetBSD 10.0sparc64Bastille-3.0.9nb13.tgz
NetBSD 10.0sparcBastille-3.0.9nb13.tgz
NetBSD 10.0x86_64Bastille-3.0.9nb13.tgz
NetBSD 10.0x86_64Bastille-3.0.9nb13.tgz
NetBSD 9.0aarch64Bastille-3.0.9nb13.tgz
NetBSD 9.0aarch64Bastille-3.0.9nb13.tgz
NetBSD 9.0earmv6hfBastille-3.0.9nb13.tgz
NetBSD 9.0earmv6hfBastille-3.0.9nb12.tgz
NetBSD 9.0earmv6hfBastille-3.0.9nb13.tgz
NetBSD 9.0earmv7hfBastille-3.0.9nb13.tgz
NetBSD 9.0earmv7hfBastille-3.0.9nb12.tgz
NetBSD 9.0earmv7hfBastille-3.0.9nb13.tgz
NetBSD 9.0i386Bastille-3.0.9nb13.tgz
NetBSD 9.0i386Bastille-3.0.9nb13.tgz
NetBSD 9.0powerpcBastille-3.0.9nb12.tgz
NetBSD 9.0powerpcBastille-3.0.9nb11.tgz
NetBSD 9.0powerpcBastille-3.0.9nb12.tgz
NetBSD 9.0sparc64Bastille-3.0.9nb13.tgz
NetBSD 9.0x86_64Bastille-3.0.9nb13.tgz
NetBSD 9.0x86_64Bastille-3.0.9nb13.tgz
NetBSD 9.3x86_64Bastille-3.0.9nb13.tgz

Binary packages can be installed with the high-level tool pkgin (which can be installed with pkg_add) or pkg_add(1) (installed by default). The NetBSD packages collection is also designed to permit easy installation from source.

Available build options

(none)

Known vulnerabilities

The pkg_admin audit command locates any installed package which has been mentioned in security advisories as having vulnerabilities.

Please note the vulnerabilities database might not be fully accurate, and not every bug is exploitable with every configuration.


Problem reports, updates or suggestions for this package should be reported with send-pr.