Re: One SLFS book or two?

Christos Gioran <[email protected]> Wed, 24 Dec 2003 01:30:02 +0200
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
> > > Something that (I think) has only briefly been touched on in the
> > > discussion about SLFS, and that is are we looking at creating one
> > > book or two? By this I mean, will there be just one book to cover
> > > both LFS and BLFS, or will there be one book for each.
>
> <..>
>
> > Just a secure toolchain, system monitors, logfile security and
> > analysis etc.  Book 2 is the network guide.
>
> I envision one book. I don't think there is really any justification in
> separating books. If you look at my proposal for chapter layout, you
> will see LFS is first. That is paramount. Why build secure apps on an
> insecure base? Then after that is done, we start BLFS. Also, as with
> BLFS, the Securing BLFS will follow a non-linear path according to what
> you have installed. If you have read any security books, you know they
> aren't small. Why should ours be? With the exception of splitting, Rob
> Day's vision is extremely close to mine. Get the LFS part out ASAP, then
> work on the rest, adding as we can. The end result will always be
> open-ended as things are constantly changing, giving us the long term
> goal Rob spoke of.

I agree to a great extent. It is the splitting that I don't think vey well of, 
but if the need for such a change appears it will happen down the road. A 
"huge" book is hard to maintain *but* it is better than the alternative of 
two volumes, each of one requires a different maintenance team and therefore 
the additional need for "keeping up with each other", as the discussion of 
links-versus-full_text to the LFS book clearly illuminated.

So, to sum up for the time being: One book, with pretty much the layout 
Archaic proposed, of slightly more advanced nature than the LFS book, with 
references to the latter and working exploits (or home made sample code) 
included/linked. What am I missing?

May I propose to start working, in parallel with this discussion, a bit on the 
packages and/or sure-to-be-included chapters such as password policy and 
partitioning?

> Archaic

-- 
himicos
-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page