Re: Secure Linux From Scratch

Robert Day <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Thu, 2003-12-18 at 22:24, ashes wrote:
> > I think we should begin at least a draft. Will start working on one really
> > soon...maybe tomorrow. Let's start pouring ideas in.
> 
> This is what I have so far, it's pretty cheesy.
> 
> Code Authoring
> All code, either in binary or source form, introduced to the system must come
> from a responcable, widely distributed, opensource project. These projects
> must employ a full discloser public bug forum.
> 
> Installed binary code
> Some sort of rating system must be used to validate code trust levels.
> Proactive testing, such as bfbtester, source code checking, such as Rats, and
> by any other means reasonable.
> 
> Minimalization of Root privileges
> In any event posible root will not be used to complete systems tasks, or run
> daemons.

Ok...   I know I am not a seasoned LFS'er or even an expert Linux
Guru...  But I do have a head ;)

First things first...   we need a roadmap sort of thing....
We need a plan of action..  ie. How the book is to come together...

Before we can get to writing, assigning (taking volunteers for) tasks,
or even looking at a release date and preliminary testing, we need to
decide how the book will be worked out. Is it going to be an add-on to
LFS, or a re-write of LFS..  Will it replace BLFS for Network Services,
or be an alongside option to it?  This, IMHO, must come before writing
can commence.
The only thing I think we can say for sure at this point in time, is
that we can begin the intorductory pages, those being the sections that
deal with general security principals and practices, without any code or
packages. 

Might I suggest that someone create, and activate something like
slfs.linuxfromscratch.org? A Page where finally agreed upon decisions
can be posted by a maintainer? Who is going to head up the SLFS book? 
Has any one person taken the leading role here? ie. the person in charge
of posting finished product, organising the troops, verifying the write
ups and ensuring proper formatting of the documents, etc. etc.  This
person should be able to post to the slfs page so us, as developers and
testers, can easily access "final decisions" easily, without having to
scroll through mailing list archives, and trying to make the call on our
own as to what has been decided....

Once that is done, and the books format and placve in the LFS community
has been decided, then we can start to develop a raodmap for the book,
and open discussions on what to include, what to provide external links
to, etc. etc.

I'd be happy to put some hours into writing up an overall security
practice and principal document, which I will hopefully base largely on
the Security-HOWTO and other site and server security documents already
in circulation...  Kind of a Coles Notes of system security, if you
will..

Let's get this ball rolling people...  I love the idea, and I can tell
there are many who would agree with me.

   Rob Day (BOFH)

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.