Gentoo Archives: gentoo-server

From: Ronan Mullally <ronan@×××.ie>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] Best practices in managing large server groups
Date: Mon, 21 May 2007 14:32:42
Message-Id: Pine.LNX.4.64.0705211525330.9909@office.4L
In Reply to: Re: [gentoo-server] Best practices in managing large server groups by Thilo Bangert
1 On Mon, 21 May 2007, Thilo Bangert wrote:
2
3 > > I've held off on using Gentoo in larger deployments because the idea of
4 > > putting a C compiler on a production box is just silly.
5 >
6 > why?
7 >
8 > some production quality software _requires_ a compiler to run.
9 > http://varnish.projects.linpro.no/wiki/FAQ
10
11 As do many rootkits. If somebody gets local access to a server with a
12 suite of development tools they're well on their way to rooting the box.
13 Removing these tools is simply a good example of security in depth.
14
15
16 -Ronan
17 --
18 gentoo-server@g.o mailing list

Replies

Subject Author
Re: [gentoo-server] Best practices in managing large server groups Arturo 'Buanzo' Busleiman <buanzo@××××××××××.ar>