Re: Secure Linux From Scratch

Robert Day <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
Just thought I would re-iterate my thoughts on this list regarding this
SLFS thread...

I think that LFS and BLFS should be in on this...
And I think SLFS should have TWO meanings..  
Secure LFS and Server LFS

Reason is this.  NO server on the internet should be put online without
some serious considerations being taken into account regarding security.
BLFS, IMHO, should remove all "Services" from the book as soon as SLFS
is done. It should be written in two stages. General Security, and
Services.

General Security should cover such topics as local security, this being
application hardening, the shadow suite, User and Group restrictions,
quotas etc. It would also be the place to discuss such topics as general
security principals and procedures, disaster avoidance and recovery, and
Security Suites such as tripwire and other such packages.

Services would cover just that. Services. Apache, sshd, ftpd, bind etc.
etc. Each subsection would then go into details about building the
package, securing it, chroots, application privelages, logging, and
anything else that is relavant to that package. 
As well, the subsections, IMHO, should also provide information on a
clean minor-version upgrade to patch security holes, and where to watch
for security bulletins if they are not in a standard location (such as
CERT) - which reminds me, links to security mailing lists such as CERT
and SecurityFocus should most DEFINATELY be part of the first section...

Anyhow, Opinions are welcome...  Flames are not so welcome ;)  

Like I said..  this is my opinion..  And as such, is likely to differ
greatly from others'

  Rob Day (BOFH)

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.