Re: SLFS book chapter proposals

jmh <[email protected]> Sat, 27 Dec 2003 13:08:24 -0500
Newsgroups gmane.linux.lfs.security
Organization Linux From Scratch
Message-ID <[email protected]>

Christos Gioran wrote:
> On Tuesday 23 December 2003 18:48, Archaic wrote:
> 
>>On Mon, Dec 22, 2003 at 11:13:43PM +0200, Christos Gioran wrote:
>>
>>>OK, that would prove to require the minimum space required and
>>>consistence with the LFS book (duplication of information in my opinion
>>>is a bad idea). But, even though this approach will prove optimum to all
>>>who have a clue, how about these "poor" fellows that start now? The would
>>>have to cross-reference between two books (three, if packages from BLFS
>>>are included), and that would cause at least confusion.
>>
>>Not when SLFS is an _extension_ to LFS. You read and build LFS first,
>>then you read SLFS to secure it.
> 
> 
> Let me see if I get this straight: You mean that HLFS should be followed from 
> people who have already built their LFS, so they have the required 
> knowledge-experience to cross-reference. I never took into consideration such 
> an approach but sounds quite resonable. As I wrote in a previous post, one 
> should know inside out (more or less) his/her system if he/she is to secure 
> it. Your proposal agrees with this point of view and eventually with me. We 
> could start in this way and see if it works.
> 

It's been very interesting to see how this has developed
and certainly look forward to the project moving forward.
Other than being a test case--no real knowledge of seurity,
linux or LFS, or programming--I don't have much to offer
so have just been lurking.

I'm wondering if the goal shouldn't be to ultimately replace
LFS with a version that includes the security elements. That
might allow a core book in a couple of years with the gcc 
3.4.4 (was that it?) and the other core parts that are not 
yet ready for release. In the interrim the ideas about
patching existing systems and apps would provide some 
immedate means of educating people like me about how
to build such a system and allow those working on producing
that knowledge in a book form to work out their presentaions
and the strucutre of a new LFS book.

Just seems to me that securing a system is about as 
fundamental as one can get and it's becoming an necessary 
part of any OS. Rather than thinking of [SH]LFS as a 
separate effort perhaps it's better to consider it a natural 
evolution of LSF. Maybe that steps on toes, I don't know who 
from the LFS efforts are involved in this or if they see no 
reason to want to get involved and would resist any such 
evolution in LFS.

My 2 cents and worth almost half of that ;-)

jmh

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page