From 92dc3748b6c236f09e7c699d4f841459fff4851c Mon Sep 17 00:00:00 2001 From: "Richard W.M. Jones" Date: Tue, 11 Oct 2011 18:04:46 +0100 Subject: [PATCH] virt-sysprep: Update TODO list (thanks Steve Grubb, Dan Berrange). --- TODO | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/TODO b/TODO index 8d5ed1d..398abdc 100644 --- a/TODO +++ b/TODO @@ -549,3 +549,18 @@ virt-sysprep ideas . install a firstboot script virt-sysprep --script=/tmp/foo.sh . run an external shell script . run external guestfish script virt-sysprep --fish=/tmp/foo.fish + - log files (thanks Steve Grubb) + . as well as the obvious log files, also + utmp/wtmp/btmp/tallylog and pam_faillock's data files + - RNG seed (Steve Grubb) + - homedirs/.ssh directory, especially /root/.ssh (Steve Grubb) + - if drives are encrypted, then dm-crypt key should be changed + and drives all re-encrypted + - /etc/pki + (Steve says ...) + Rpm uses nss. Nss sets up its crypto database in + /etc/pki. Depending on how long the machine ran before cloning, you + may have picked up some certificates or things. This is an area + that you would want to look into. + - secure erase of inodes etc using scrub (Steve Grubb) + - touch /.autorelabel if we create any new files (thanks Dan Berrange) -- 1.8.3.1