Gentoo Archives: gentoo-hardened

From: Ed W <lists@××××××××××.com>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Recommended "hardened" setup if using Xen
Date: Sat, 28 Jan 2006 17:30:29
Message-Id: 43DBA9B9.7080302@wildgooses.com
1 Further to my last post. I am quite determined to use Xen on this new
2 coloco box. It may solve some issues going forward
3
4 With that in mind, and considering the box is a remote headless server,
5 and that I don't have much hardened experience, what would be the most
6 secure gentoo install path that I should consider right now? I'm happy
7 to be told that the default 2005.1 build is probably going to be the
8 best option if for example I am treading the less tested path by trying
9 to use Xen?
10
11 At the moment I am downloading the stage1 piessp experimental stages
12 with a view to starting with these and upgrading to the new gcc compiler
13 right away. I was going to get that booting, then add in the patches to
14 allow the root partition to sit on EVMS, then finally trying to get Xen
15 kernel built and running.
16
17 Am I on a hiding to nothing here? Is there a compromise path that would
18 be more suitable bearing in mind I don't have much time to admin this
19 box and workaround issues?
20
21 The box will be used primarily as a commercial mailserver + webserver +
22 ecommerce apps + some customised inhouse applications (I think you can
23 see the obvious reason to consider Xen and partition some of these
24 applications)
25
26 Grateful for your thoughts
27
28 Ed W
29 --
30 gentoo-hardened@g.o mailing list