1 |
Ah but I should have mentioned my boss is a stingy so and so who is |
2 |
definitely not keen on spending the kind of bucks that would give us |
3 |
such a cluster for that matter he's not even prepared to get me another |
4 |
box with the same hardware as the web or mail servers (dual xeon) to use |
5 |
as a test/development box. So pretty much all crp that hits the fan |
6 |
(such as the bios issue that made the system fans go off when over |
7 |
heating) is my problem to deal with at whatever time of day or night -- |
8 |
(wish I could say the pay was enough...) |
9 |
|
10 |
-----Original Message----- |
11 |
From: xyon [mailto:xyon@×××××××××××.com] |
12 |
Sent: Wednesday, January 25, 2006 12:37 PM |
13 |
To: gentoo-server@l.g.o |
14 |
Subject: Re: [gentoo-server] (Hardened) Converting production |
15 |
Gentoomail/web server to |
16 |
|
17 |
hardened-sources is a great kernel to use. With all the GRSecurity and |
18 |
PaX options enabled it's quite a step above stock. |
19 |
|
20 |
RBAC (ACL) is a wonderful way to lock down the system, but takes a long |
21 |
time to get right. I would highly recommend mirroring your production |
22 |
environment with a dev environment to play with this feature. |
23 |
|
24 |
With your company's policy of 0 downtime, they have a |
25 |
load-balanced/cluster environment, correct? If so, rebooting one server |
26 |
shouldn't be a huge deal.. if they do not have a load-balanced/cluster |
27 |
environment, 0 downtime is going to be very difficult to maintain. Just |
28 |
my 2 cents. ;) |
29 |
|
30 |
On Wed, 2006-01-25 at 12:09 +0200, Jean Blignaut wrote: |
31 |
> (Hi I posted this before in the "portscanning worm?" thread but |
32 |
> thought that people might not have seen it there cause I've not had |
33 |
> any comments/replys?) |
34 |
> |
35 |
> |
36 |
> |
37 |
> I have often considered and even tried a couple of times to setup a |
38 |
> hardened box however I get confused between all the different options |
39 |
> and all the different implications. What with Selinux Grsecurity 1/2 |
40 |
> RSBAC PIE etc. etc. |
41 |
> |
42 |
> |
43 |
> |
44 |
> Also the kernel patching concerns me a bit, I would much rather not |
45 |
> have to search around an battle to patch kernels my self if at all |
46 |
> possible. |
47 |
> |
48 |
> I don't get to upgrade the kernel on my production servers very often |
49 |
> since company policy is 0 downtime. |
50 |
> |
51 |
> |
52 |
> |
53 |
> Also Because these are production servers in use by 1000s of customers |
54 |
> I would have to find a hardened kernel (or what ever) that would have |
55 |
> as small an impact on the current workings and config of the systems |
56 |
> involved. |
57 |
> |
58 |
> |
59 |
> |
60 |
> I have all my partitions formatted (and kernels built) with support |
61 |
> for security labels, but that's as far as I've gotten. Also the idea |
62 |
> of splitting up roots permissions into roles is an interesting |
63 |
> prospect but I've yet to find decent documentation on how to |
64 |
> implement/use POSIX ROLES |
65 |
> |
66 |
> |
67 |
> |
68 |
|
69 |
|
70 |
|
71 |
-- |
72 |
gentoo-server@g.o mailing list |
73 |
|
74 |
|
75 |
-- |
76 |
gentoo-server@g.o mailing list |