Gentoo Archives: gentoo-hardened

From: Matthew Thode <prometheanfire@g.o> (prometheanfire)
To: gentoo-hardened@l.g.o
Cc: powerman@××××××××.name
Subject: Re: [gentoo-hardened] New Server, considering hardened, need pointers to tfm...
Date: Sun, 11 Dec 2011 16:51:30
Message-Id: 20111211104915.6cb2fbd0@khorne.mthode.org
In Reply to: Re: [gentoo-hardened] New Server, considering hardened, need pointers to tfm... by Alex Efros
1 On Sun, 11 Dec 2011 16:53:02 +0200
2 Alex Efros <powerman@××××××××.name> wrote:
3
4 > Hi!
5 >
6 > On Sun, Dec 11, 2011 at 02:25:19PM +0000, Sven Vermeulen wrote:
7 > > > 1) How can
8 > > > 4.2.4.1. Root Logon Through SSH Is Not Allowed
9 > > > increase security, if we're already using
10 > > > 4.2.4.2. Public Key Authentication Only
11 > > > Disabling root may have sense with password auth, but with
12 > > > keys it is just useless inconvenience.
13 > >
14 > > I read somewhere that security is about making things more
15 > > inconvenient for malicious people than for authorized ones.
16 > >
17 > > For me, immediately logging in as root is not done. I want to limit
18 > > root access through the regular accounts on the system (with
19 > > su(do)). I never had the need to log on as root immediately myself.
20 >
21 > Understood. But I still don't see how this can increase security.
22 >
23 > > hardening measures, glsa-check, cvechecker and the like to mitigate
24 > > risks of
25 >
26 > Been there, done that, it doesn't work: in average, after 1-1.5 years
27 > of security-only updates we end with next one security update which
28 > depends on few other packages which in turn pull in 80% of other
29 > @world updates. So we've to emerge world anyway every ~1.5 years, but
30 > such delayed updates wasn't tested by anyone and usually gives a lot
31 > of troubles resulting in server offline for several days. Daily world
32 > updates are much ease to manage, even with needs to check these
33 > updates on test servers first, before updating production servers.
34 > (And daily updates usually easy to rollback and debug in case of
35 > unexpected troubles.) Because of this I don't think Gentoo is capable
36 > to act as LTS-release with security-only updates like some other
37 > distributives.
38 >
39
40 Well, you don't wait years, just months between updates. I have
41 glsa-check running daily on my systems and update when it tells me to.
42 On top of that I update at least monthly, usually weekly (though I
43 could probably go every six months and be fine).
44
45 --
46 Matthew Thode (prometheanfire)

Attachments

File name MIME type
signature.asc application/pgp-signature