Automating some best-practice/common-sense [was: Keeping hosts updated]
Jaco <[email protected]> Sat, 26 Nov 2011 15:08:15 +1300
| Newsgroups | gmane.org.user-groups.linux.new-zealand.general |
|---|---|
| Organization | Workshop Enterprises Ltd. |
| Message-ID | <[email protected]> |
> Ubuntu have a commercial service called landscape that does what you > want as well, and it looks like it's either run from the internet, or > you can have a local Landscape server installed. A combination of Landscape & Puppet seems like the (long-term) ideal solution, but required some time & effort to get right. I'll need to make a commitment to AppArmor/SELinux to deploy & maintain policy, such as application/process-whitelisting, etc. What's spurned me to do this, beyond a very few systems, is this good report (posted before; might've been elsewhere): Top 35 Mitigation Strategies http://www.dsd.gov.au/infosec/top-mitigations/top35mitigationstrategies-list.htm Quick summary of top points: * Patch OS * Patch apps * Restrict privileges & scope * Whilelist I've been doing some of this for some time (to a greater & lesser extent), but I want to take the monotonous leg-work out of recurring repetitive tasks (i.e. automation). Much of this seems like common sense, which really isn't all that common. Thanks for the pointers & please keep them coming. Cheers - Jaco _______________________________________________ NZLUG mailing list [email protected] http://www.linux.net.nz/cgi-bin/mailman/listinfo/nzlug