Hacker News new | ask | show | jobs
by kstrauser 1416 days ago
The whole securelevel mechanism is nice. You can only increase its value at runtime, never decrease it without rebooting. At higher levels, you can’t modify firewall rules. If you configure the server to boot into a high securelevel, you can make the machine effectively read-only until you boot it with console access.