Re: Certifying a RedHat Install
"Scott Taylor" <[email protected]>
| Newsgroups | gmane.comp.security.linux |
|---|---|
| Message-ID | <[email protected]> |
abe said: > Thanks for everyone's answers so far, but perhaps I need to restate my > question... > > >>>What can I do to assure my customer that I have installed no back > doors for myself.<<< Well, if you start doing things like that to your customers you won't have many left will you? You could ask them to have someone knowledgeable stand over your shoulder, or ask them to hire someone they trust. Maybe you need to charge more so they can trust you more. $100/h USD should do it. ;) > rpm -Va will check the size, date & permissions of all rpm installed > files. I don't know if it will do an md5 or similar. But such a command > would be a quick integrity test, yes? No. If you are so malicious that you would leave a backdoor for yourself, what is to stop you from installing a script of any type to make it look like you didn't? > md5's of most of the system will allow direct comparisons with a known > good RH9 install. And what about the files you don't want them to know about, such as your so-called backdoor? > I have to use RH9 as the application they need only works on RH9. > Otherwise, yes I'd've installed a more current version or different > flavor... BS. RedHat Enterprize Linux ES 3 runs pretty much exactly as RH9 and is the current RedHat supported release with it's somewhat working up2date product, it's easy to keep current. I would venture a bet that anything that runs on RH9 will be able to run on just about any Linux distro, with a bit of work, but will most likely run on the latest RH release. Good luck. -- Scott