1 |
Kwon wrote: |
2 |
>> Considering that VMware server uses kernel modules for operation on the |
3 |
>> host system. Also that it likes to run as root (I haven't checked to see |
4 |
>> if it can run as an unprivileged user) and that it wants to use |
5 |
>> xinetd... I would say that you should at least be careful with it. |
6 |
> |
7 |
> Yes! Indeed! My conclusion is that white box hardware costs are so cheap |
8 |
> these days (CAD$300 to CAD$500 a box). I would rather have different |
9 |
> physical systems in a DMZ rather than a software solution using VMWare. |
10 |
> |
11 |
|
12 |
100% ACK - there's nothing safer than separate hardware boxes. And yes, |
13 |
there are practical issues that keep me away from using VMWare in a |
14 |
high-risk production environment (i. e. stand-alone webserver, proxy, |
15 |
firewall...) |
16 |
|
17 |
But as far as I remember the original question was whether a para- or a |
18 |
full virtualization provide more security - from the theoretical point |
19 |
of view I still stick to the full virtualization as the more secure |
20 |
solution. In real life, there may still be additional things to be |
21 |
considered (such as resource needs, quality of the implementation...) |
22 |
|
23 |
Just my $0,02 |
24 |
-- |
25 |
gentoo-hardened@g.o mailing list |