Gentoo Archives: gentoo-server

From: xyon <xyon@×××××××××××.com>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] (Hardened) Converting production Gentoo mail/web server to
Date: Wed, 25 Jan 2006 10:38:40
Message-Id: ME-1F1i16-00006o-JQ@indigorobot.com
In Reply to: [gentoo-server] (Hardened) Converting production Gentoo mail/web server to by Jean Blignaut
1 hardened-sources is a great kernel to use. With all the GRSecurity and
2 PaX options enabled it's quite a step above stock.
3
4 RBAC (ACL) is a wonderful way to lock down the system, but takes a long
5 time to get right. I would highly recommend mirroring your production
6 environment with a dev environment to play with this feature.
7
8 With your company's policy of 0 downtime, they have a
9 load-balanced/cluster environment, correct? If so, rebooting one server
10 shouldn't be a huge deal.. if they do not have a load-balanced/cluster
11 environment, 0 downtime is going to be very difficult to maintain. Just
12 my 2 cents. ;)
13
14 On Wed, 2006-01-25 at 12:09 +0200, Jean Blignaut wrote:
15 > (Hi I posted this before in the ´portscanning worm?¡ thread but
16 > thought that people might not have seen it there cause Iÿve not had
17 > any comments/replys?)
18 >
19 >
20 >
21 > I have often considered and even tried a couple of times to setup a
22 > hardened box however I get confused between all the different options
23 > and all the different implications. What with Selinux Grsecurity 1/2
24 > RSBAC PIE etc. etc.
25 >
26 >
27 >
28 > Also the kernel patching concerns me a bit, I would much rather not
29 > have to search around an battle to patch kernels my self if at all
30 > possible.
31 >
32 > I don't get to upgrade the kernel on my production servers very often
33 > since company policy is 0 downtime.
34 >
35 >
36 >
37 > Also Because these are production servers in use by 1000s of customers
38 > I would have to find a hardened kernel (or what ever) that would have
39 > as small an impact on the current workings and config of the systems
40 > involved.
41 >
42 >
43 >
44 > I have all my partitions formatted (and kernels built) with support
45 > for security labels, but that's as far as I've gotten. Also the idea
46 > of splitting up roots permissions into roles is an interesting
47 > prospect but I've yet to find decent documentation on how to
48 > implement/use POSIX ROLES
49 >
50 >
51 >
52
53
54
55 --
56 gentoo-server@g.o mailing list