From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([208.92.234.80] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1RZmcc-0001MO-9i for garchives@archives.gentoo.org; Sun, 11 Dec 2011 16:51:30 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id E622C21C06E; Sun, 11 Dec 2011 16:51:15 +0000 (UTC) Received: from mx1.mthode.org (rrcs-24-173-105-85.sw.biz.rr.com [24.173.105.85]) by pigeon.gentoo.org (Postfix) with ESMTP id 84CF021C01F for ; Sun, 11 Dec 2011 16:50:27 +0000 (UTC) Received: from khorne.mthode.org (unknown [IPv6:2001:470:e1cc:2:2677:3ff:fe25:a674]) (using TLSv1 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by mx1.mthode.org (Postfix) with ESMTPSA id 96933BB9A; Sun, 11 Dec 2011 11:50:26 -0500 (EST) Date: Sun, 11 Dec 2011 10:49:15 -0600 From: Matthew Thode (prometheanfire) To: gentoo-hardened@lists.gentoo.org Cc: powerman@powerman.name Subject: Re: [gentoo-hardened] New Server, considering hardened, need pointers to tfm... Message-ID: <20111211104915.6cb2fbd0@khorne.mthode.org> In-Reply-To: <20111211145302.GE1990@home.power> References: <4EE3BE6B.6050507@libertytrek.org> <20111210145204.39ec9cba@khorne.mthode.org> <20111211101851.GA1810@gentoo.org> <20111211122043.GD1990@home.power> <20111211142519.GA12313@gentoo.org> <20111211145302.GE1990@home.power> X-Mailer: Claws Mail 3.7.10 (GTK+ 2.24.5; x86_64-pc-linux-gnu) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-hardened@lists.gentoo.org Reply-to: gentoo-hardened@lists.gentoo.org Mime-Version: 1.0 Content-Type: multipart/signed; micalg=PGP-SHA1; boundary="Sig_/Vqg3u5KKtwwdL4/ISh1mNWs"; protocol="application/pgp-signature" X-Archives-Salt: 5ff26ab0-ebc7-46dc-923b-ff9b537e4e87 X-Archives-Hash: 5e8ef0244339cec9c1377e1ca196e66f --Sig_/Vqg3u5KKtwwdL4/ISh1mNWs Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: quoted-printable On Sun, 11 Dec 2011 16:53:02 +0200 Alex Efros wrote: > Hi! >=20 > On Sun, Dec 11, 2011 at 02:25:19PM +0000, Sven Vermeulen wrote: > > > 1) How can > > > 4.2.4.1. Root Logon Through SSH Is Not Allowed > > > increase security, if we're already using > > > 4.2.4.2. Public Key Authentication Only > > > Disabling root may have sense with password auth, but with > > > keys it is just useless inconvenience. > >=20 > > I read somewhere that security is about making things more > > inconvenient for malicious people than for authorized ones. > >=20 > > For me, immediately logging in as root is not done. I want to limit > > root access through the regular accounts on the system (with > > su(do)). I never had the need to log on as root immediately myself. >=20 > Understood. But I still don't see how this can increase security. >=20 > > hardening measures, glsa-check, cvechecker and the like to mitigate > > risks of >=20 > Been there, done that, it doesn't work: in average, after 1-1.5 years > of security-only updates we end with next one security update which > depends on few other packages which in turn pull in 80% of other > @world updates. So we've to emerge world anyway every ~1.5 years, but > such delayed updates wasn't tested by anyone and usually gives a lot > of troubles resulting in server offline for several days. Daily world > updates are much ease to manage, even with needs to check these > updates on test servers first, before updating production servers. > (And daily updates usually easy to rollback and debug in case of > unexpected troubles.) Because of this I don't think Gentoo is capable > to act as LTS-release with security-only updates like some other > distributives. >=20 Well, you don't wait years, just months between updates. I have glsa-check running daily on my systems and update when it tells me to. On top of that I update at least monthly, usually weekly (though I could probably go every six months and be fine). --=20 Matthew Thode (prometheanfire) --Sig_/Vqg3u5KKtwwdL4/ISh1mNWs Content-Type: application/pgp-signature; name=signature.asc Content-Disposition: attachment; filename=signature.asc -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.17 (GNU/Linux) iQIcBAEBAgAGBQJO5N8SAAoJECRx6z5ArFrDz+MQANkaDYQFWGXdl2g0TdHvitZS k0SqEHxkedYSs7fQKdmCPmraccTfthOnYrKUOn/kC86bqa/9OcjPHnNorEFrw3Kt ZqMwT0WqEeSf9Jl1NeeSQWNbWVH7BXXuOFdjaqEXm7PSLmIt2TZ4wQag7JAUeXWR i5AL89eKnGj6h3Ard9JxW/+6GlWcLDZTu94UlITbTRfCBFzJr2EXzhwJin04XqGq MmUKvWQYa1B+CKV/Xz39S60MCu/kTQfCpC3PgyA4315OasSCtcQ6ZwudHeKZxtBA KD/pp0SGSQWgOaQIbmTJrnJcsITYvwvk/10ZJwsoFyU6MuJPcIm5v47hN3sTd/JT 8g71jhBBK4MDJz8u3jcjBj85qsfhzJZwe8guxAhuji/c0OncsZObvR62vIz9lhrN H8PDwSP93q+IhkXGWhIlBMjnqra+exoN2uXFAnLFzELq04SjO75eVCMvKIQYEalC xaOSw/Lf8z8l1g0q0n9ME+JM3JheBwq5YnBbb8hngm6ADSKqXVqlN0lz6+bxU9qF OSi641gYRz5vPFBL31H9Rc/ZYGHDAfuSWRJfmczyggsoKW33ahQzlyD9moStCadY 7fz3GNPFFxBmLzkyz6DIZkzI2Af4Pu9ukxxRrha+94PfhL3o7/p4BI/+JYLpr7zB o0KUe3kje0+J4RS2FW7o =Ul67 -----END PGP SIGNATURE----- --Sig_/Vqg3u5KKtwwdL4/ISh1mNWs--