Review needed, putting yast2-security in shape

Ancor Gonzalez Sosa <[email protected]> Thu, 11 Jun 2015 10:47:25 +0200
Newsgroups gmane.linux.suse.opensuse.devel,gmane.linux.suse.security
Message-ID <[email protected]>
YaST2-Security, the YaST module to configure local security settings, is
aging. There is a quite deep analysis about the problems here
https://docs.google.com/document/d/1BFVou4YrRoc4vPCkofs-Qo2C9b-lWIbuMBiGk3Oc0WU/edit?usp=sharing

The plan described in the document is a mid-term goal. In the short term
(next week), the goal is to do less disruptive changes. To be concrete,
just:

- Remove any reference to runlevels
- Update the list of security settings (currently "home
  workstation", "networked worstation" and "network server")
- Update the list of mandatory services (it will still be independent
  of the security setting for the time being)
- Update the list of extra allowed services (same as above)

We are already working with the following lists, feedback is highly
appreciated.

New list of security settings:
 - Workstation
 - Server

New list of mandatory services:
 - systemd
 - systemd-journald
 - systemd-dmevented
 - systemd-udevd
 - systemd-logind
 - dbus-daemon
 - rsyslogd
 - polkitd
 - cron
 - SuSEfirewall
 - auditd

New list of extra (harmless) services:
 - wickedd
 - nscd
 - postfix
 - ntpd
 - sshd
 - haveged


Anything you miss? Anything you thing should not be there?

Thanks.
-- 
Ancor González Sosa
YaST Team at SUSE Linux GmbH
-- 
To unsubscribe, e-mail: [email protected]
To contact the owner, e-mail: [email protected]