Re: Secure Linux From Scratch
Archaic <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Tue, Dec 02, 2003 at 08:04:45PM +0000, Ian Molton wrote: > On Tue, 2 Dec 2003 13:00:09 -0500 > "Frank R. Wesselmann" <[email protected]> wrote: > > > A guided approach to hardening an LFS system would certainly be much > > appreciated, so SLFS would be a great book to have. > > seconded. WARNING, I'm currently heavily medicated and my thinking is a little fuzzy. :) Okay, if it's going to become a reality we need to start formulating a plan of attack. The first one I would consider is book goals and format/layout. I believe the goal of LFS is the way to go. That is, that the purpose of the project is to create a book that teaches, not an operating system. The end result provides an OS, but learning should still be the main objective. As far as layout, there's two main ways I see: 1) Write a book the builds a new system from scratch. PROS: Less compile time CONS: Duplicates a vast majority of the LFS book. (Harder to maintain) 2) Write a book that systematically goes through all the packages in an LFS system and configures them or re-compiles them as needed. Many packages won't be touched as they don't have security-related options to configure. PROS: Smaller book, little duplication CONS: Longer compile times (can be overcome by using links in the LFS book that reference the SLFS book much like it currently does for hints). I also think an SLFS book version should strictly match an LFS-book version. This fits well with layout #2 and allows for better testing and easier problem solving. Of course, one could use more recent packages, but there would be no guarantee to the casual reader that it would work. I really hope to see some replies of interest to this as I think it is something that many people can benefit greatly from. The learning curve for security issues is high as it is and is only exascerbated by the fact that there is a lot of outdated (or just plain wrong) information floating around. The creation of a practical, ready-to-use repository of security information would be useful for the simple home-system, up to a network of production servers. Granted, the book can't teach everything, but it can sure teach some practical principles while building a more hardened system. Just like with the LFS book, the end of the book is not the end of the journey, but rather the beginning. -- Archaic "I hold it, that a little rebellion, now and then, is a good thing, and as necessary in the political world as storms in the physical." - Thomas Jefferson, Letter to James Madison, January 30, 1787 -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page