Re: Secure Linux From Scratch

Christos Gioran <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
> Ok...   I know I am not a seasoned LFS'er or even an expert Linux
> Guru...  But I do have a head ;)
>
> First things first...   we need a roadmap sort of thing....
> We need a plan of action..  ie. How the book is to come together...
>
> Before we can get to writing, assigning (taking volunteers for) tasks,
> or even looking at a release date and preliminary testing, we need to
> decide how the book will be worked out. Is it going to be an add-on to
> LFS, or a re-write of LFS..  Will it replace BLFS for Network Services,
> or be an alongside option to it?  This, IMHO, must come before writing
> can commence.

Although I wrote in a post that I think this book should be a re-write, no 
comments have been made on that. Especially the networking part could be a 
complete book on its own. Awaiting responces.

> The only thing I think we can say for sure at this point in time, is
> that we can begin the intorductory pages, those being the sections that
> deal with general security principals and practices, without any code or
> packages.

That's a very good start....perhaps the essence of the book, since it will 
provide the foundation of the knowledge on which the system will be build. 
Any LFS is about learning. All else come next.

> Might I suggest that someone create, and activate something like
> slfs.linuxfromscratch.org? A Page where finally agreed upon decisions
> can be posted by a maintainer?

IMO, this list houses the project so far and does it well. When the need rises 
it will be obvious, and implemented ASAP.

> Who is going to head up the SLFS book?
> Has any one person taken the leading role here? ie. the person in charge
> of posting finished product, organising the troops, verifying the write
> ups and ensuring proper formatting of the documents, etc. etc.  This
> person should be able to post to the slfs page so us, as developers and
> testers, can easily access "final decisions" easily, without having to
> scroll through mailing list archives, and trying to make the call on our
> own as to what has been decided....

Can't realy say about that, the need is not clear as of yet and only a douzen 
different people have shown direct interest (ie posted in the list). It's too 
soon, don't you think? 

> Once that is done, and the books format and placve in the LFS community
> has been decided, then we can start to develop a raodmap for the book,
> and open discussions on what to include, what to provide external links
> to, etc. etc.
>
> I'd be happy to put some hours into writing up an overall security
> practice and principal document, which I will hopefully base largely on
> the Security-HOWTO and other site and server security documents already
> in circulation...  Kind of a Coles Notes of system security, if you
> will..

HUGE task, I will be glad to help you in (or take a part on me) The 
secure-programs-HOWTO is a must include too. Others will come in mind, will 
look through my bibliography and come up with some.

> Let's get this ball rolling people...  I love the idea, and I can tell
> there are many who would agree with me.
>
>    Rob Day (BOFH)

Well said

himicos

PS. Is anyone else subscribed to any security realated list, like 
security-basics or Bugtraq? If not, may I suggest to go ahead and do it, they 
provide insight to a myriad of subjects.
-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.