1 |
On Monday 09 February 2004 19:44, James Dennis wrote: |
2 |
> Anyway, my point is, it would be nice if Gentoo came with something |
3 |
> similar to what OpenBSD has. It's like tripwire, but stripped down and |
4 |
> built into cron right from the get go to check your system for file |
5 |
> changes. As Gentoo is going down the path of making things more secure |
6 |
> out of the box (with the removal of setuid on things as an example) I |
7 |
> think we could benefit from something like this. I know cron isn't a |
8 |
> required install, but would it be possible to have something be ready |
9 |
> to go once a cron daemon was installed? |
10 |
|
11 |
You can use 'aide' to watch for file changes. |
12 |
A more basic question IMHO is: Is gentoo the right distribution if you need |
13 |
a secure system? Normally on a system which needs to be secure you don't |
14 |
have any compiler, do not update the software as often as gentoo 'require' |
15 |
this etc. - I like gentoo very much for development/desktop systems, but to |
16 |
build a server which needs to be stable and does not need to be often |
17 |
maintained I prefer debian stable or similar. |
18 |
|
19 |
-- |
20 |
"Those who would give up essential liberty, to purchase a little temporary |
21 |
safety, deserve neither liberty nor safety." - Benjamin Franklin |
22 |
|
23 |
|
24 |
-- |
25 |
gentoo-security@g.o mailing list |