Re: Secure Linux From Scratch
"Vyrl Sutton" <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
----- Original Message ----- From: "Archaic" <[email protected]> To: "LFS Security Discussion List" <[email protected]> Sent: Thursday, December 11, 2003 23:36 Subject: Re: Secure Linux From Scratch > On Tue, Dec 02, 2003 at 08:04:45PM +0000, Ian Molton wrote: > > On Tue, 2 Dec 2003 13:00:09 -0500 > > "Frank R. Wesselmann" <[email protected]> wrote: > > > > > A guided approach to hardening an LFS system would certainly be much > > > appreciated, so SLFS would be a great book to have. > > > > seconded. > > WARNING, I'm currently heavily medicated and my thinking is a little > fuzzy. :) > > Okay, if it's going to become a reality we need to start formulating a > plan of attack. The first one I would consider is book goals and > format/layout. > > I believe the goal of LFS is the way to go. That is, that the purpose of > the project is to create a book that teaches, not an operating system. > The end result provides an OS, but learning should still be the main > objective. > > As far as layout, there's two main ways I see: > > 1) Write a book the builds a new system from scratch. > > PROS: Less compile time > > CONS: Duplicates a vast majority of the LFS book. (Harder to maintain) > > 2) Write a book that systematically goes through all the packages in an > LFS system and configures them or re-compiles them as needed. Many > packages won't be touched as they don't have security-related options to > configure. > > PROS: Smaller book, little duplication > > CONS: Longer compile times (can be overcome by using links in the LFS > book that reference the SLFS book much like it currently does for > hints). > > I also think an SLFS book version should strictly match an LFS-book > version. This fits well with layout #2 and allows for better testing > and easier problem solving. Of course, one could use more recent > packages, but there would be no guarantee to the casual reader that it > would work. > > I really hope to see some replies of interest to this as I think it is > something that many people can benefit greatly from. The learning curve > for security issues is high as it is and is only exascerbated by the > fact that there is a lot of outdated (or just plain wrong) information > floating around. The creation of a practical, ready-to-use repository of > security information would be useful for the simple home-system, up to a > network of production servers. Granted, the book can't teach everything, > but it can sure teach some practical principles while building a more > hardened system. Just like with the LFS book, the end of the book is not > the end of the journey, but rather the beginning. > > -- > Archaic > > "I hold it, that a little rebellion, now and then, is a good thing, and > as necessary in the political world as storms in the physical." > > - Thomas Jefferson, Letter to James Madison, January 30, 1787 > > -- > I like option 2 better. Will this be written in XML? My understanding of the XML conversion for the LFS book is to let people checkout either an expert or newbie version of the LFS book. If this is true then why couldn't there be an option to checkout a basic version LFS or a SLFS book? This would avoid having a second book, if you have to read two books to get SLFS built, mistakes will be made. If you could read one book to build SLFS then fewer mistakes will be made. Will there be a book or hint for BLFS since BLFS recompiles some packages? Vyrl -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page