Gentoo Archives: gentoo-hardened

From: Alex Efros <powerman@××××××××.name>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] New Server, considering hardened, need pointers to tfm...
Date: Sun, 11 Dec 2011 14:54:02
Message-Id: 20111211145302.GE1990@home.power
In Reply to: Re: [gentoo-hardened] New Server, considering hardened, need pointers to tfm... by Sven Vermeulen
1 Hi!
2
3 On Sun, Dec 11, 2011 at 02:25:19PM +0000, Sven Vermeulen wrote:
4 > > 1) How can
5 > > 4.2.4.1. Root Logon Through SSH Is Not Allowed
6 > > increase security, if we're already using
7 > > 4.2.4.2. Public Key Authentication Only
8 > > Disabling root may have sense with password auth, but with keys it is
9 > > just useless inconvenience.
10 >
11 > I read somewhere that security is about making things more inconvenient for
12 > malicious people than for authorized ones.
13 >
14 > For me, immediately logging in as root is not done. I want to limit root
15 > access through the regular accounts on the system (with su(do)). I never had
16 > the need to log on as root immediately myself.
17
18 Understood. But I still don't see how this can increase security.
19
20 > hardening measures, glsa-check, cvechecker and the like to mitigate risks of
21
22 Been there, done that, it doesn't work: in average, after 1-1.5 years of
23 security-only updates we end with next one security update which depends
24 on few other packages which in turn pull in 80% of other @world updates.
25 So we've to emerge world anyway every ~1.5 years, but such delayed
26 updates wasn't tested by anyone and usually gives a lot of troubles
27 resulting in server offline for several days. Daily world updates are much
28 ease to manage, even with needs to check these updates on test servers
29 first, before updating production servers. (And daily updates usually easy
30 to rollback and debug in case of unexpected troubles.) Because of this I
31 don't think Gentoo is capable to act as LTS-release with security-only
32 updates like some other distributives.
33
34 --
35 WBR, Alex.

Replies