Re: Secure Linux From Scratch

[email protected]
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
Pardon this openbsd advocacy.

OpenBSD also has the non-exec stack features from pax sorted out. They somehow 
made a staticly linked base (/bin and /sbin) which is smaller then a 
dynamicly linked Linux base system. I think they're down to about 4-5 suid 
binaries. They have XFree86, syslogd, sshd, kadmin, portmap, identd, and 
others, doing root privlege seperation. I've also noticed Pappy (from gentoo) 
is getting a lot of his info from openbsd. I'm not discontinuing anything, I 
want to see how openbsd has put their stuff together. This may have to do 
with their auditing/coding, but I also noticed openbsd base binaries segfault 
much less when tested with bfbtester (patch and wc segfault twice on openbsd, 
and about 100 times on Linux). Also, openbsd is migrating to gcc3, so in the 
next few months to a year they might release some propolice related patches 
that gentoo and everyone else might use.

The first thing I need to know about the SLFS book is the security policy. 
What is the criteria for the base system. Military grade or hobbiest?

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.