| Newsgroups |
gmane.linux.lfs.security |
| Message-ID |
<[email protected]> |
Pardon this openbsd advocacy.
OpenBSD also has the non-exec stack features from pax sorted out. They somehow
made a staticly linked base (/bin and /sbin) which is smaller then a
dynamicly linked Linux base system. I think they're down to about 4-5 suid
binaries. They have XFree86, syslogd, sshd, kadmin, portmap, identd, and
others, doing root privlege seperation. I've also noticed Pappy (from gentoo)
is getting a lot of his info from openbsd. I'm not discontinuing anything, I
want to see how openbsd has put their stuff together. This may have to do
with their auditing/coding, but I also noticed openbsd base binaries segfault
much less when tested with bfbtester (patch and wc segfault twice on openbsd,
and about 100 times on Linux). Also, openbsd is migrating to gcc3, so in the
next few months to a year they might release some propolice related patches
that gentoo and everyone else might use.
The first thing I need to know about the SLFS book is the security policy.
What is the criteria for the base system. Military grade or hobbiest?
--
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page