1 |
As i see workstations, you don't offer remote shells, that would make it a |
2 |
server already.. my hacked adsl modem with nat only allows sshd from the |
3 |
outside... and sets state on sessions from the inside.. so when i want i can |
4 |
ssh in, but that's just me... everything else is blocked from the internet... |
5 |
|
6 |
i checked out grsecurity before and it looks promising, but the openwall |
7 |
patch from solardesigner is nice as well.. what's best? i wouldn't enable it |
8 |
standard as it can block certain things too... |
9 |
|
10 |
just make it an option.. |
11 |
|
12 |
-- |
13 |
Guido |
14 |
|
15 |
Ok, but i think grsecurity is something else. This seems to be a |
16 |
user-mode application. |
17 |
|
18 |
In my opinion you can enable grsecurity with some options on |
19 |
workstation's, too. |
20 |
Have you ever look at the new options from a grsecurity patched kernel. |
21 |
What's could be against to make a workstation computer same secure as a |
22 |
server? |
23 |
|
24 |
Through the sysctl interface you could apply this to any kernel and |
25 |
active the options |
26 |
you want through a config-file and a init.d script i have posted some |
27 |
days ago. |
28 |
But I really think that all workstations could enable some options as |
29 |
default. |
30 |
|
31 |
Regards |
32 |
|
33 |
Sebastian Werner |
34 |
|
35 |
Am 24.12.2001 10:57:46, schrieb Guido Bakker <guidob@g.o>: |
36 |
>I think it should be an option in the installer in the future... |
37 |
>Security patches for a workstation have no use in my opinion... |
38 |
> |
39 |
>You could also look at the attachment which is from SUN... |
40 |
> |
41 |
>-- |
42 |
>Guido |
43 |
> |
44 |
> |
45 |
>Hey |
46 |
> |
47 |
>i think it's nice to patch gentoo's default kernel with grsecurity |
48 |
>(www.grsecurity.net). You integrate so many patches. Grsecurity enhance |
49 |
>the security for the normal internet-user. I think it's a must in any |
50 |
>default-kernel! |
51 |
> |
52 |
>Regards |
53 |
> |
54 |
>Sebastian Werner |
55 |
> |
56 |
> |
57 |
> |
58 |
>_______________________________________________ |
59 |
>gentoo-dev mailing list |
60 |
>gentoo-dev@g.o |
61 |
>http://lists.gentoo.org/mailman/listinfo/gentoo-dev |