new systems should come with an /etc/rlimit.conf file.
#!/bin/sh
#
-# $Id: netbsd_improvements.txt,v 1.50 2015/08/04 01:17:20 mmondor Exp $
+# $Id: netbsd_improvements.txt,v 1.51 2015/08/04 01:21:28 mmondor Exp $
#
# If too early at boot, the sysctl commands somehow fail.
Ideally, writing to protected files should optionally be forbidden;
otherwise, their cached verified-signature status should be forgotten in
order for the next use to verify the signature again.
+ An alternative would be signatures loaded from a database, possibly using
+ fileassoc(9).
- NPF
- Lack of proper diagnostics/stats