Re: Secure Linux From Scratch
Bill's LFS Login <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 17 Dec 2003, Tushar Teredesai wrote: > Archaic wrote: > > ><snip> > >If it's to get off the > >ground, we need more developers. > > > I think there are many other folks who would be interested, maybe after > the lfs-dev post there would be more volunteers. > > I would suggest that a small group come with a POA before posting the > RFC. That would make it easier for people to join in on the discussion. Yes. I was going to suggest the following yesterday, but ran out of time. Several folks that replied to the OP might collaborate off-list to gen not only a POA, but also working group to gen a preliminary design. This need not involve developers. This would just layout a possible framework of various things that must be considered, the "mechanics" of how this can be accomplished. As example, there are several mechanical paths to staying current with LFS. A totally separate book, maintained as a sub-project, a "copy" of the book that is then fixed up and published or a "patch set" that is available for the book that is applied by the end user (or applied by the new rendering processes, when available). I like this last one - it seems to minimize maintenance effort and leave the SLFS folks free to do the more time-consuming and "interesting" stuff. And the opportunities for other benefits to the project should also be considered. As example, we could assume (request) that SLFS monitor security advisories, pre-test new releases for security issues and advise the core LFS folks of concerns/results when it seems appropriate. LFS core could advise SLFS (or SLFS could monitor CVS activity) that a new pkg/version was being considered. LFS test would probably want to offer services, but might need more resources (folks, additional platforms, ...). There are also issues of impact that should be considered. If security-X is applied, what detrimental effect, if any, is seen in operation-Y, package-Z, ALFS, BLFS, ... Summary: as you know, not a minor undertaking. Ramifications abound in terms of effect on products, users, resource consumption, required support services (internal and to the community), concurrency issues, ... This will require some coordination. -- NOTE: I'm on a new ISP, if I'm in your address book ... Bill Maltby lfsbillATearthlinkDOTnet Fix line above & use it to mail me direct. -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page