1 |
Hi! |
2 |
|
3 |
On Sun, Dec 11, 2011 at 02:25:19PM +0000, Sven Vermeulen wrote: |
4 |
> > 1) How can |
5 |
> > 4.2.4.1. Root Logon Through SSH Is Not Allowed |
6 |
> > increase security, if we're already using |
7 |
> > 4.2.4.2. Public Key Authentication Only |
8 |
> > Disabling root may have sense with password auth, but with keys it is |
9 |
> > just useless inconvenience. |
10 |
> |
11 |
> I read somewhere that security is about making things more inconvenient for |
12 |
> malicious people than for authorized ones. |
13 |
> |
14 |
> For me, immediately logging in as root is not done. I want to limit root |
15 |
> access through the regular accounts on the system (with su(do)). I never had |
16 |
> the need to log on as root immediately myself. |
17 |
|
18 |
Understood. But I still don't see how this can increase security. |
19 |
|
20 |
> hardening measures, glsa-check, cvechecker and the like to mitigate risks of |
21 |
|
22 |
Been there, done that, it doesn't work: in average, after 1-1.5 years of |
23 |
security-only updates we end with next one security update which depends |
24 |
on few other packages which in turn pull in 80% of other @world updates. |
25 |
So we've to emerge world anyway every ~1.5 years, but such delayed |
26 |
updates wasn't tested by anyone and usually gives a lot of troubles |
27 |
resulting in server offline for several days. Daily world updates are much |
28 |
ease to manage, even with needs to check these updates on test servers |
29 |
first, before updating production servers. (And daily updates usually easy |
30 |
to rollback and debug in case of unexpected troubles.) Because of this I |
31 |
don't think Gentoo is capable to act as LTS-release with security-only |
32 |
updates like some other distributives. |
33 |
|
34 |
-- |
35 |
WBR, Alex. |