RE: LFS Paper on Secure Servers
"EC" <[email protected]> Sat, 1 May 2004 22:03:11 +0200
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
>-----Message d'origine----- >De : [email protected] [mailto:lfs-security- >[email protected]] De la part de Bruce Dubbs >Envoyé : samedi 1 mai 2004 08:58 >À : [email protected]; BLFS Development List; LFS Security >Discussion List >Objet : LFS Paper on Secure Servers > >I've been working on a major paper based on LFS for the last few months >and have now come to the point where it should be released. The paper >is at: > >http://www.linuxfromscratch.org/~bdubbs/secure-linux.pdf >http://www.linuxfromscratch.org/~bdubbs/secure-linux.html > >The files are also available at: > >http://sol.sac.accd.edu/~bdubbs/secure-linux.pdf >http://sol.sac.accd.edu/~bdubbs/secure-linux.html > >so you might want to use that site to not overload the main lfs site. > >The html file is not what I consider well rendered and is a single file, >but I wanted to get the paper released. I intend to redo the format in >the new LFS XML style that Manuel and others have been working on so hard. > >The files are fairly large (306K html, 493K pdf). The paper is 59 pages >plus about 100 pages of appendicies, so its not a quick read. I am >interested in maintaing the paper, so if there are any suggestions for >improvement, they are welcome. > >The abstract reads: > >"When securing a server, most administrators start with a commercial >distribution and try to modify the configuration to >eliminate security problem areas. The problem is that most distributions >have many packages installed that are unnecessary on a server. For >instance, the RedHat 9 distribution loads a minimum of 115 packages. >Knowing what these packages are and the security implementations of each >is very difficult. > >This paper takes a different approach. It starts by building a base >system from "scratch" using the techniques from the Linux From Scratch >project. To that base, the administration and security tools required to >manage the system are added. Finally, the server applications are >installed. Great job. Very interesting and useful. I will probably test it in a few weeks for my own environement. I no security expert, though. I do have small comments/questions/suggestions.. 1) The use of sendmail as an MTA .. since it is secure oriented, isn't is more interesting to put postfix or qmail instead ? 2) Going to nALFS for the build will be great. I am newbie to LFS, but have already built dozens of LFS with it. It works great, profiles are quick to write, easy to maintain/change. 3) isn't it interesting to use grsecurity in such environement ? Again, I'm no expert, but building such an security oriented system with grsecurity and a well desgined ACL seems useful. Hope my comments were useful.. Emmanuel. -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page