Re: SLFS book chapter proposals

Bill's LFS Login <[email protected]> Sat, 27 Dec 2003 13:50:33 -0500 (EST)
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Sat, 27 Dec 2003, jmh wrote:

> Christos Gioran wrote:
> > On Tuesday 23 December 2003 18:48, Archaic wrote:
> >
> >>On Mon, Dec 22, 2003 at 11:13:43PM +0200, Christos Gioran wrote:
> >>
> >>><snip>

> I'm wondering if the goal shouldn't be to ultimately replace
> LFS with a version that includes the security elements. That
> might allow a core book in a couple of years with the gcc
> 3.4.4 (was that it?) and the other core parts that are not
> yet ready for release.

The problem would be the goals of the two projects are really in
conflict. LFS aims to provide a certain basic edu in the areas of just
building a GNU/Linux system from an existing host and leaving the user
with a base system that allows them to do many other things (BLFS,
security, make workstations, gateways, whatever).

SLFS looks to be more concerned with *implementation* of a basic
hardened system (including beyond LFS applications) while possibly
providing some education. That assumes my read on the postings are
valid.

Even if SLFS ends up bing more edu oriented, and less pragmatic
application oriented, there are still several "blockers" to making a
combined project (book) easily. The threads to-date touch on all these
issues.

><snip>

> Just seems to me that securing a system is about as
> fundamental as one can get and it's becoming an necessary
> part of any OS.

Really dependent on your orientation/POV. For a user with little/no use
for internet services or a home network that does not connect
frequently, etc., they may have little need for all the secure stuff.
A simple ipchains/iptables that drops all incoming not originated on
their host may be sufficient. For them, SLFS would be *far* from
"fundamental". My current gateway acts this way (permitting only smtp
connects originating outside) and since I have no MS mailers that might
start up processes based on mail contents, I'm *fairly* secure. I'm sure
others have similar setups.

> Rather than thinking of [SH]LFS as a
> separate effort perhaps it's better to consider it a natural
> evolution of LSF. Maybe that steps on toes, I don't know who
> from the LFS efforts are involved in this or if they see no
> reason to want to get involved and would resist any such
> evolution in LFS.

Politics are always possible. But the core argument will be objectives
and workload related. Any experience trying to manage projects will lead
one to be careful about trying to combine projects with different basic
goals and/or large workload issues. Especially when the workforce is
very diverse and all volunteer. Can't satisfy enough of the people
enough of the time to make the aggravation worthwhile.

>
> My 2 cents and worth almost half of that ;-)
>
> jmh

-- 
NOTE: I'm on a new ISP, if I'm in your address book ...
Bill Maltby
lfsbillATearthlinkDOTnet
Fix line above & use it to mail me direct.
-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page