1 |
hardened-sources is a great kernel to use. With all the GRSecurity and |
2 |
PaX options enabled it's quite a step above stock. |
3 |
|
4 |
RBAC (ACL) is a wonderful way to lock down the system, but takes a long |
5 |
time to get right. I would highly recommend mirroring your production |
6 |
environment with a dev environment to play with this feature. |
7 |
|
8 |
With your company's policy of 0 downtime, they have a |
9 |
load-balanced/cluster environment, correct? If so, rebooting one server |
10 |
shouldn't be a huge deal.. if they do not have a load-balanced/cluster |
11 |
environment, 0 downtime is going to be very difficult to maintain. Just |
12 |
my 2 cents. ;) |
13 |
|
14 |
On Wed, 2006-01-25 at 12:09 +0200, Jean Blignaut wrote: |
15 |
> (Hi I posted this before in the ´portscanning worm?¡ thread but |
16 |
> thought that people might not have seen it there cause Iÿve not had |
17 |
> any comments/replys?) |
18 |
> |
19 |
> |
20 |
> |
21 |
> I have often considered and even tried a couple of times to setup a |
22 |
> hardened box however I get confused between all the different options |
23 |
> and all the different implications. What with Selinux Grsecurity 1/2 |
24 |
> RSBAC PIE etc. etc. |
25 |
> |
26 |
> |
27 |
> |
28 |
> Also the kernel patching concerns me a bit, I would much rather not |
29 |
> have to search around an battle to patch kernels my self if at all |
30 |
> possible. |
31 |
> |
32 |
> I don't get to upgrade the kernel on my production servers very often |
33 |
> since company policy is 0 downtime. |
34 |
> |
35 |
> |
36 |
> |
37 |
> Also Because these are production servers in use by 1000s of customers |
38 |
> I would have to find a hardened kernel (or what ever) that would have |
39 |
> as small an impact on the current workings and config of the systems |
40 |
> involved. |
41 |
> |
42 |
> |
43 |
> |
44 |
> I have all my partitions formatted (and kernels built) with support |
45 |
> for security labels, but that's as far as I've gotten. Also the idea |
46 |
> of splitting up roots permissions into roles is an interesting |
47 |
> prospect but I've yet to find decent documentation on how to |
48 |
> implement/use POSIX ROLES |
49 |
> |
50 |
> |
51 |
> |
52 |
|
53 |
|
54 |
|
55 |
-- |
56 |
gentoo-server@g.o mailing list |