RE: Certifying a RedHat Install

"Gunnoe, Jason" <[email protected]>
Newsgroups gmane.comp.security.linux
Message-ID <0DDFFE69420F6540ADE95DEFB1D9821C01A6CF9B@ohcinmail01.tl.thomcorp.net>
These have all been good suggestions IMHO. With the exception that FC1
is not production ready.  It is as good, or better than 9.0.  Stay away
from FC2 in production unless you have an RHCE or equal admin around.

Start by clearly defining the server role and responsibilities.

Use a known good installation source verified by MD5 or other signature
from a reputable site (redhat.com)

Never put a system in production (or on the wire, hmmm... tricky one you
say) without first patching/updating it.

Eliminate files and packages that you don't need.

Turn off or don't install services that you don't need.

Establish a local firewall. TCP wrappers, PAM extensions if necessary,
SE Linux if you are adventurous. 

Sign the file system, print off the installed packages.

Write up a customer 'sign-off' sheet, ... 'as of this date...' that
includes the scope of work, the signatures (tripwire or like summaries)
configuration, and files/versions installed.  Hand the customer the
liability document and a copy of the removable media with the signatures
all in one good session.

Most importantly you'll need a definitive beginning and end to the
engagement.  Be sure to draw that line.

Go grab a drink and celebrate.

Jason Gunnoe RHCE
Security Officer
Thomson Learning
(513) 229-1147

-----Original Message-----
From: Michael LaSalvia [mailto:[email protected]] 
Sent: Wednesday, July 14, 2004 5:15 PM
To: 'abe'; [email protected]
Subject: RE: Certifying a RedHat Install

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

The base install of rh 9.0 has a vuln in the kernel that a normal
user can gain root access. I believe the vuln was bork overflow. I
would suggest upgrading the kernel before delivery.

Michael LaSalvia
LCA, TICSA, CCSA, CSI


- -----Original Message-----
From: abe [mailto:[email protected]] 
Sent: Wednesday, July 14, 2004 1:38 PM
To: [email protected]
Subject: Certifying a RedHat Install

My client wants me to certify there are no back doors in the RedHat 9
server we are going to deliver.  It's a base RH9 install with a few 
extra RPM's, like Guarddog.

Question is what's the best way for us to certify this?
*  rpm -Va ?
*  A global md5 on each file?

Also, what's the best way to minimize liability if they are hacked? 
I 
don't want to get sued because the were negligent.

Thanks,

Abe




-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.8 for non-commercial use <http://www.pgp.com>

iQA/AwUBQPWiSdKAGcNwMOHTEQJpXwCeJywd4Xipzz+eF8NddFIkWfkmSf8AnRTG
zygHmTq5XTPsolbVLCMp5FD5
=BMA/
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.