Re: Secure Linux From Scratch

"Frank R. Wesselmann" <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <003001c3b8fe$2b6ca410$9865fea9@Cantrell>
<lurker emerging from the shadows>

Hi y'all, thought I'd add a "consumer voice" to this discussion:

A guided approach to hardening an LFS system would certainly be much
appreciated, so SLFS would be a great book to have.  But for it to be a
realistic project, I think a limited scope must be defined.  There is just
no way a project like this can feasibly dig up vulnerabilities in the
various packages.  That's the job of the package maintainers and the user
base at large.

Our community could, however, make an organized effort to keep abreast of
discoveries and fixes (this list seems to do at least some of that).
Customizations, such as those already mentioned in this thread for gcc, also
would seem appropriate and most likely candidates for reference in the LFS
book, though they would need to be thoroughly discussed.  But I have yet to
see anyone make any mention of the most basic and obvious issue:
configuration.

The LFS book (and BLFS) certainly seem to make a serious effort to avoid
SUID vulnerabilities and to provide a reasonably safe but useful base
configuration.  What is sorely lacking, however, is a more fundamental
description of the need (or lack thereof) for SUID executables and what the
consequences of flipping this bit really are, strategies for individual
packages, and other issues along these lines.  Yes, all this is available in
the packages' documentation -- mostly and to varying degrees of completeness
and comprehensibility.  But that's an awful lot of work for the LFS user,
just for the base LFS system which is almost useless by itself.

A book that can help us configure a limited but useful system (i.e. a
controlled environment) to maximize security would seem to be supremely
useful.  So it would have to be SLFS and SBLFS in one, otherwise I think it
should just be an appendix in LFS.  IMHO, that is.

frw
<fading back into the darkness>

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.