Re: Secure Linux From Scratch
Robert Day <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
Just thought I would re-iterate my thoughts on this list regarding this SLFS thread... I think that LFS and BLFS should be in on this... And I think SLFS should have TWO meanings.. Secure LFS and Server LFS Reason is this. NO server on the internet should be put online without some serious considerations being taken into account regarding security. BLFS, IMHO, should remove all "Services" from the book as soon as SLFS is done. It should be written in two stages. General Security, and Services. General Security should cover such topics as local security, this being application hardening, the shadow suite, User and Group restrictions, quotas etc. It would also be the place to discuss such topics as general security principals and procedures, disaster avoidance and recovery, and Security Suites such as tripwire and other such packages. Services would cover just that. Services. Apache, sshd, ftpd, bind etc. etc. Each subsection would then go into details about building the package, securing it, chroots, application privelages, logging, and anything else that is relavant to that package. As well, the subsections, IMHO, should also provide information on a clean minor-version upgrade to patch security holes, and where to watch for security bulletins if they are not in a standard location (such as CERT) - which reminds me, links to security mailing lists such as CERT and SecurityFocus should most DEFINATELY be part of the first section... Anyhow, Opinions are welcome... Flames are not so welcome ;) Like I said.. this is my opinion.. And as such, is likely to differ greatly from others' Rob Day (BOFH) -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page