Re: SLFS book chapter proposals
Bill's LFS Login <[email protected]> Sat, 27 Dec 2003 13:50:33 -0500 (EST)
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Sat, 27 Dec 2003, jmh wrote: > Christos Gioran wrote: > > On Tuesday 23 December 2003 18:48, Archaic wrote: > > > >>On Mon, Dec 22, 2003 at 11:13:43PM +0200, Christos Gioran wrote: > >> > >>><snip> > I'm wondering if the goal shouldn't be to ultimately replace > LFS with a version that includes the security elements. That > might allow a core book in a couple of years with the gcc > 3.4.4 (was that it?) and the other core parts that are not > yet ready for release. The problem would be the goals of the two projects are really in conflict. LFS aims to provide a certain basic edu in the areas of just building a GNU/Linux system from an existing host and leaving the user with a base system that allows them to do many other things (BLFS, security, make workstations, gateways, whatever). SLFS looks to be more concerned with *implementation* of a basic hardened system (including beyond LFS applications) while possibly providing some education. That assumes my read on the postings are valid. Even if SLFS ends up bing more edu oriented, and less pragmatic application oriented, there are still several "blockers" to making a combined project (book) easily. The threads to-date touch on all these issues. ><snip> > Just seems to me that securing a system is about as > fundamental as one can get and it's becoming an necessary > part of any OS. Really dependent on your orientation/POV. For a user with little/no use for internet services or a home network that does not connect frequently, etc., they may have little need for all the secure stuff. A simple ipchains/iptables that drops all incoming not originated on their host may be sufficient. For them, SLFS would be *far* from "fundamental". My current gateway acts this way (permitting only smtp connects originating outside) and since I have no MS mailers that might start up processes based on mail contents, I'm *fairly* secure. I'm sure others have similar setups. > Rather than thinking of [SH]LFS as a > separate effort perhaps it's better to consider it a natural > evolution of LSF. Maybe that steps on toes, I don't know who > from the LFS efforts are involved in this or if they see no > reason to want to get involved and would resist any such > evolution in LFS. Politics are always possible. But the core argument will be objectives and workload related. Any experience trying to manage projects will lead one to be careful about trying to combine projects with different basic goals and/or large workload issues. Especially when the workforce is very diverse and all volunteer. Can't satisfy enough of the people enough of the time to make the aggravation worthwhile. > > My 2 cents and worth almost half of that ;-) > > jmh -- NOTE: I'm on a new ISP, if I'm in your address book ... Bill Maltby lfsbillATearthlinkDOTnet Fix line above & use it to mail me direct. -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page