Re: Secure Linux From Scratch

Tushar Teredesai <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
Archaic wrote:

>Yes, but local can quickly become remote if you have telnetd or sshd
>running. I assume many of the sections in the book would be skipped by
>some, just like many skip the KDE section of BLFS. It's still a matter
>of choice built around a core framework. That is what makes the entire
>LFS concept so beautiful.
>  
>
Well said :-)

>Of course, at times there will be lag, but the linking of the SLFS
>version to the LFS version doesn't mean packages have to stay the same.
>Taking your kernel example. The SLFS-5 book would assume a base LFS-5
>install. Therefore, the kernel section would say get 2.4.23 and apply
>the relavant patches, etc, because if assuming an LFS version, we _know_
>the reader has a vulnerable kernel. All changes of this sort could be
>numbered by patch-level increments in order to maintain the numbering
>cohesion to the LFS book. Example: LFS-5.0 and SLFS-5.0 are released. A
>kern bug is found. SLFS fixes it and increments to SLFS-5.0.1, 5.0.2,
>etc. Eventually becoming 5.1 when LFS does. Also, all attempts would be
>made (just like in BLFS) to keep CVS synced with changes to LFS-CVS.
>BLFS had to keep OpenOffice instructions synced to what LFS-CVS was
>doing).
>  
>
That is exactly how we are planning to do it for BLFS. Makes it a bit 
easier to maintain.

>If it's to get off the
>ground, we need more developers.
>
I think there are many other folks who would be interested, maybe after 
the lfs-dev post there would be more volunteers.

I would suggest that a small group come with a POA before posting the 
RFC. That would make it easier for people to join in on the discussion.

-- 
Tushar Teredesai
   http://www.linuxfromscratch.org/~tushar/
   http://www.geocities.com/tushar/


-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.