Re: Secure Linux From Scratch

Bill's LFS Login <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Wed, 17 Dec 2003, Tushar Teredesai wrote:

> Archaic wrote:
>
> ><snip>

> >If it's to get off the
> >ground, we need more developers.
> >
> I think there are many other folks who would be interested, maybe after
> the lfs-dev post there would be more volunteers.
>
> I would suggest that a small group come with a POA before posting the
> RFC. That would make it easier for people to join in on the discussion.

Yes. I was going to suggest the following yesterday, but ran out of
time. Several folks that replied to the OP might collaborate off-list to
gen not only a POA, but also working group to gen a preliminary design.
This need not involve developers. This would just layout a possible
framework of various things that must be considered, the "mechanics" of
how this can be accomplished.

As example, there are several mechanical paths to staying current with
LFS. A totally separate book, maintained as a sub-project, a "copy" of
the book that is then fixed up and published or a "patch set" that is
available for the book that is applied by the end user (or applied by
the new rendering processes, when available). I like this last one - it
seems to minimize maintenance effort and leave the SLFS folks free to do
the more time-consuming and "interesting" stuff.

And the opportunities for other benefits to the project should also be
considered. As example, we could assume (request) that SLFS monitor
security advisories, pre-test new releases for security issues and
advise the core LFS folks of concerns/results when it seems appropriate.

LFS core could advise SLFS (or SLFS could monitor CVS activity) that a
new pkg/version was being considered.

LFS test would probably want to offer services, but might need
more resources (folks, additional platforms, ...).

There are also issues of impact that should be considered. If security-X
is applied, what detrimental effect, if any, is seen in operation-Y,
package-Z, ALFS, BLFS, ...

Summary: as you know, not a minor undertaking. Ramifications abound in
terms of effect on products, users, resource consumption, required
support services (internal and to the community), concurrency issues,
...

This will require some coordination.

-- 
NOTE: I'm on a new ISP, if I'm in your address book ...
Bill Maltby
lfsbillATearthlinkDOTnet
Fix line above & use it to mail me direct.
-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.