Re: Secure Linux From Scratch
ashes <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Utopia Inc |
| Message-ID | <[email protected]> |
I suggest the SLFS book be the same as the LFS book, and SBLFS be like BLFS, as far as layout. With things like, Pax, et_dyn, propolice, libsafe, or audited packages, it doesn't make any sence to use one but not the other. Everyone has the option to only follow parts of the book they want to anyway. (S)BLFS are components that not everyone will use, like networking. I also think its a good idea to keep networking out of SLFS since its a massive subject and should be seperated for better detail. >From what I understand et_dyn is broken in gcc-3.3. So without adding more patches, we could downgrade to gcc-3.2, or upgrade to gcc-3.4 with a backport/patch.. and that needs glibc-2.3.3. Just something to consider, but we'll need to do one of these to take advantage of Pax. I need to update the propolice hint and I'll start auditing coreutils, and try to come up with a security/auditing policy draft. This presents another problem. The coreutils team doesn't want to hear about bugs in v5.0, they expect me to use their cvs version, so if fixes are found/made, we will either have to use more patches, or the cvs version, at least untill a stable slfs book version is made. I'm not on the lfs-dev list, is this discussion going to move there? -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page