Gentoo Archives: gentoo-server

From: Jean Blignaut <jean@×××××××.biz>
To: gentoo-server@l.g.o
Subject: RE: [gentoo-server] (Hardened) Converting production Gentoomail/web server to
Date: Wed, 25 Jan 2006 11:09:33
Message-Id: B31C4776605A3840B544482E1A94C5C93ADDC5@eagle.birds
1 Ah but I should have mentioned my boss is a stingy so and so who is
2 definitely not keen on spending the kind of bucks that would give us
3 such a cluster for that matter he's not even prepared to get me another
4 box with the same hardware as the web or mail servers (dual xeon) to use
5 as a test/development box. So pretty much all crp that hits the fan
6 (such as the bios issue that made the system fans go off when over
7 heating) is my problem to deal with at whatever time of day or night --
8 (wish I could say the pay was enough...)
9
10 -----Original Message-----
11 From: xyon [mailto:xyon@×××××××××××.com]
12 Sent: Wednesday, January 25, 2006 12:37 PM
13 To: gentoo-server@l.g.o
14 Subject: Re: [gentoo-server] (Hardened) Converting production
15 Gentoomail/web server to
16
17 hardened-sources is a great kernel to use. With all the GRSecurity and
18 PaX options enabled it's quite a step above stock.
19
20 RBAC (ACL) is a wonderful way to lock down the system, but takes a long
21 time to get right. I would highly recommend mirroring your production
22 environment with a dev environment to play with this feature.
23
24 With your company's policy of 0 downtime, they have a
25 load-balanced/cluster environment, correct? If so, rebooting one server
26 shouldn't be a huge deal.. if they do not have a load-balanced/cluster
27 environment, 0 downtime is going to be very difficult to maintain. Just
28 my 2 cents. ;)
29
30 On Wed, 2006-01-25 at 12:09 +0200, Jean Blignaut wrote:
31 > (Hi I posted this before in the "portscanning worm?" thread but
32 > thought that people might not have seen it there cause I've not had
33 > any comments/replys?)
34 >
35 >
36 >
37 > I have often considered and even tried a couple of times to setup a
38 > hardened box however I get confused between all the different options
39 > and all the different implications. What with Selinux Grsecurity 1/2
40 > RSBAC PIE etc. etc.
41 >
42 >
43 >
44 > Also the kernel patching concerns me a bit, I would much rather not
45 > have to search around an battle to patch kernels my self if at all
46 > possible.
47 >
48 > I don't get to upgrade the kernel on my production servers very often
49 > since company policy is 0 downtime.
50 >
51 >
52 >
53 > Also Because these are production servers in use by 1000s of customers
54 > I would have to find a hardened kernel (or what ever) that would have
55 > as small an impact on the current workings and config of the systems
56 > involved.
57 >
58 >
59 >
60 > I have all my partitions formatted (and kernels built) with support
61 > for security labels, but that's as far as I've gotten. Also the idea
62 > of splitting up roots permissions into roles is an interesting
63 > prospect but I've yet to find decent documentation on how to
64 > implement/use POSIX ROLES
65 >
66 >
67 >
68
69
70
71 --
72 gentoo-server@g.o mailing list
73
74
75 --
76 gentoo-server@g.o mailing list

Replies

Subject Author
RE: [gentoo-server] (Hardened) Converting production Gentoomail/web server to xyon <xyon@×××××××××××.com>