Re: Server installation over the network

"Lucas C. Villa Real" <[email protected]> Wed, 12 Apr 2017 12:35:12 -0300
Newsgroups gmane.linux.distributions.gobo.general
Message-ID <CAAvzgtYOJNPEB5h3N3=jYgXGw3FTXQJWRPP85sCykYLwiVn_BA@mail.gmail.com>
On Wed, Apr 12, 2017 at 7:17 AM, Anshuman Aggarwal <
[email protected]> wrote:

> On 12 April 2017 at 10:34, Hisham <[email protected]> wrote:
> > On 12 April 2017 at 01:57, Anshuman Aggarwal
> > <[email protected]> wrote:
> >> On 10 April 2017 at 23:35, Lucas C. Villa Real <[email protected]>
> wrote:
> >>> On Mon, Apr 10, 2017 at 2:33 PM, Anshuman Aggarwal
> >>> <[email protected]> wrote:
> >>>>
> >>>> I have started pruning the PackageNames.txt file for a server install.
> >>>> Can we split this file into a say ServerPackageNames.txt and append
> >>>> the GUIPackageNames.txt and the ISO build script can be given an
> >>>> option to make either one? This will allow us to keep server and gui
> >>>> ISO builds around without double maintenance?
> >>>>
> >>>> Regards
> >>>> Anshuman
> >>>>
> >>>
> >>> To be fair, I wouldn't like to touch the installer right now. We're
> going to
> >>> have a complete rewrite of it very soon, now that our abstraction
> toolkit
> >>> (AbsTk) library has been ported to Lua. We'll likely want to go with a
> >>> different approach to the installation of remote packages instead of
> the
> >>> traditional "network install", too.
> >>>
> >>> Thanks,
> >>> Lucas
> >>>
> >>
> >> I suggest that the new installer have multiple installation options
> >> for packages like minimal, server or at least GUI/No GUI
> >> (headless/virtual vs desktop/laptop use cases).
> >
> > One very important reason we don't advertise Gobo as a server OS is
> > because we do not publish security patches with the necessary speed
> > required by a server OS running always-connected network services. I
> > do not recommend running Gobo as a server, and as a matter of fact, as
> > of 016.01, I recommend against it.
> >
> > If one wants to install it on a server one is free to do so, but one
> > would have to track security updates for all installed packages by
> > hand and that is really risky business.
> >
> > -- Hisham
>
> That is a very good point that got overlooked. Although in todays day
> of high speed internet available on even desktop/laptops/mobiles they
> are quite vulnerable but mostly they are behind a NAT router which
> acts as a firewall.
>
> However if one has a good linux firewall (say shorewall) installed,
> then only the linux kernel, the firewall and other open services need
> to be kept up to date right? That may be doable for a SOHO server,
> IMHO :-)
>
> If we are worried about an out of date application which is making an
> outgoing connection then all the Gobo desktops would be vulnerable
> (assuming you spend an 8 hour day working on it)?


The difference is that our desktop machines won't be exposing services to
the Internet (as opposed to a server). I usually bind services to the
loopback interface only, something which is not possible when you need to
enable remote access to them.

Lucas

_______________________________________________
gobolinux-users mailing list
[email protected]
http://lists.gobolinux.org/mailman/listinfo/gobolinux-users