Re: SLFS as an extention to LFS

Robert Day <[email protected]> Wed, 24 Dec 2003 12:56:16 -0500
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
Well, Misread... Big time.

On Wed, 2003-12-24 at 12:28, Archaic wrote:
> On Tue, Dec 23, 2003 at 08:16:44PM -0500, Robert Day wrote:
> > 
> > Anyhow, if it is decided finally that SLFS is to be patched into LFS,
> > then I cannot change that, but I also cannot help much.
> 
> I still don't know where you get this from. I never said it should be
> patched into LFS, so I will say it again to hopefully make it as clear
> as possible.
> 
> 1. Build LFS.
> 2. Rebuild LFS (as necessary) and configure the system you have built by
> reading SLFS.
> 
If you mean build SLFS using LFs as a host, then that is fine.  But I
don;t see why it is needed to build LFS as a host. If a user is
competent and knows how to build stuff and is genuinely interested in
security, they should be able to pick up SLFS book, and build the entire
system from there, using their existing distro as the host. This is not
building Fort Knox on a sandpit..  This is building a steel reinforced
concrete foundation on top of a sand pit. Once the concrete is poured,
the sand is irelavant, as the fort is built on the concrete.
Building LFS, then rebuilding parts of it, patching security patches
into parts of it, then adding onto it - that is where I find fault... 
Maybe my arguments are unfounded, but the self-contained argument will
stand. And I am not alone in that thought there.

> Now, if you want a shortcut, then apply the patches as neccesary while
> building LFS. I can't see the difference other than avoiding recompiling
> time, but I cannot advocate writing a book that enforces this technique
> as that is massive duplication of a good book that is already being
> produced.
> 
The two books are completely different.  LFS builds a barebones base,
with no emphasis on security or servers, or desktops - just a base. It
is a learning tool you can use to build a Linux box, and understand how
and why everything is there. BLFS is a logical addition as it adds
packages that are useful to some people. LFS can become a server, a
workstation, a devlopment base, whatever. But it does not have security
at it's base, as a major design goal. SLFS IS just that -
Security-focused...  unless someone changed the definition of SLFS that
is ;)

> > - I would feel constantly like I am building Fort Knox on top of a
> > sandpit, instead of a reinforced concrete foundation with all the latest
> > alarm technology.
> 
> So, how did secure OS's get built? My guess is that they had a host at
> some point. That is building on top of a sandpit. Where's the
> difference?
> 
See above. notes re sandpits.

> > Until someone takes the initiative and gets some work done, and gets
> > something rolling other than mailing list chatter, all it will be is
> > chatter and decisions that never get made :(   
> 
> Work is being done, though I've not seen any from you, so your complaint
> seems a little misplaced. Anyway, if you think it not worth your effort
> to produce this "inferior" OS, then by all means, fine, but please don't
> try to hinder our goals with your poor attitude.
> 
I am not trying to hinder anyone's goals...  I am trying to get
something started..   A documetn of this scope cannot be a tossed
salad.  Can it?  It has to have structure, goals, maps, plans, etc. etc.
and all the work has to be collaborated. That is what I am not seeing,
and that is what i have a problem with.  You don't see any work from me
cause I don;t see a solid plan in place, or even an agreement as per
direction.  I'm doing a fair bit of work planning out layouts,
organisations, goals, jobs, tests etc. that all have to be done before
much work can commence.  If no one agrees with me on that point (as is
becoming clear that many do not) then I am wasting my time, which is why
I am not volunteering much.  I could spend hours building a colaberation
server where everyone can come together and see the plans, the goals,
the open tasks that need to be completed before Milestone one is
reached, and before internal release is ready for testing, and finally
release date...  but if no one cares to follow a specific roadmap and
set out project goal;s, and no one can agree on any of the basics, I
would be wasting my time, and the project would end up split up to two
different projects - or more.


Herein ends my rant and rave, and my arguments.
 
Flames have at it... but off list - there is enough clutter...  no need
to flame me on the list.

  Rob Day (BOFH)


-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page