Gentoo Archives: gentoo-user

From: Mark Knecht <markknecht@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Increasing security [WAS: Rooted/compromised Gentoo, seeking advice [Solved?]
Date: Mon, 16 Aug 2010 15:30:03
Message-Id: AANLkTimLViM6-58etrCd5kuX4LDc290-TF_tBEZYaPEZ@mail.gmail.com
In Reply to: Re: [gentoo-user] Increasing security [WAS: Rooted/compromised Gentoo, seeking advice [Solved?] by Bill Longman
1 On Mon, Aug 16, 2010 at 7:16 AM, Bill Longman <bill.longman@×××××.com> wrote:
2 > On 08/14/2010 12:32 PM, Jarry wrote:
3 >> On 13. 8. 2010 21:05, Enrico Weigelt wrote:
4 >>> * Bill Longman<bill.longman@×××××.com>  wrote:
5 >>>
6 >>>> Basically just run VMWare/Virtualbox etc and put the services in there.
7 >>>
8 >>> well, these solutions are way "bigger" (iow: more resource
9 >>> intensive), since they run a complete operation system instance
10 >>> within the virtual machine.
11 >>
12 >> That is why I picked up Linux-VServer (actually, first I tried
13 >> OpenVZ but could not make it run). It is a kind of compromise,
14 >> where all guests share the same kernel. This brings certain
15 >> security implications, but on the other side, I can run dozens
16 >> of guest on a moderate machine, with 4-cores and 8GB memory
17 >> (i.e. a guest running bind takes just about 20MB of memory)...
18 >
19 > This looks rather interesting, Jarry. Is it simply a matter of compiling
20 > the vserver-sources and util-vserver? Did it take much time to set up
21 > the kernel for your box? Or is it pretty much a typical kernel setup?
22 > Any good tools in the util-vserver package?
23 >
24 >> The only service running on my "host" (main system) is sshd,
25 >> which I secured as much as I could. Everything else (web, mail,
26 >> dns, ftp, syslog, X, and plenty of users' services) runs on its
27 >> own guest-system, chrooted in addition (where it was possible).
28 >
29 > Sounds very efficient.
30 >
31 > TIA,
32 >
33 > Bill
34
35 Certainly looks interesting.
36
37 I guess the baselayout-vserver packages is somehow for setting up each
38 of the guests?
39
40 QUESTION: Where does X run? In the host or separate copies in each guest?
41
42 For a long time I've wanted to set up a single piece of hardware for
43 my parents, but with two screens, two keyboards, two mice. Each user
44 would have what they expect in front of them physically but it's
45 really a single computer. Can that be done using this software?
46
47 Thanks,
48 Mark

Replies