public inbox for gentoo-server@lists.gentoo.org
 help / color / mirror / Atom feed
From: "Spahn, Daniel" <DSpahn@cuh2a.com>
To: "gentoo-server@lists.gentoo.org" <gentoo-server@lists.gentoo.org>
Subject: RE: [gentoo-server] Server Packages for Gentoo
Date: Tue, 30 Sep 2008 13:10:19 -0500	[thread overview]
Message-ID: <BA4D8FC573225D4798B6569AAF63F6AD0209169679@OMAC-INEXMBX01.intranet.hdr> (raw)
In-Reply-To: <749691.55185.qm@web65402.mail.ac4.yahoo.com>

----Original Message-----
From: BRM [mailto:bm_witness@yahoo.com]
Sent: Tuesday, September 30, 2008 1:36 PM
To: gentoo-server@lists.gentoo.org
Subject: Re: [gentoo-server] Server Packages for Gentoo

How's this one?

Sorry about that - ( I tried something different this time, but for the most part...) unfortunately I can't do anything about it since it's Yahoo's webmail interface...Also why I'm not replying in-line, but at the top.

Ben



----- Original Message ----
From: Robert Bridge <robert@robbieab.com>
To: gentoo-server@lists.gentoo.org
Sent: Tuesday, September 30, 2008 1:28:46 PM
Subject: Re: [gentoo-server] Server Packages for Gentoo

On Tue, 30 Sep 2008 09:17:42 -0700 (PDT)
BRM <bm_witness@yahoo.com> wrote:

> That's a matter of choosing what you install; but that's not specific
> to Gentoo.
>
> MySQL on Gentoo is not going to be any different than MySQL on RHEL
> or SLES. However, stability - due to differences in versions,
> patches, etc. - might be different; but should be close to the same.

Except the Gentoo version will move a lot faster, potentially causing
problems...

BRM: Can you please fix you mail client so it includes the in-reply-to
and/or references headers so that it stops spawning a new thread
every time you reply.


Now that I've seen some ideas, here is what I was thinking by enterprise-level software:

Software that is secure within its domain, dedicated to a function, runs lean and without bloat, stable, as isolated from the OS as possible, and scalable. Software in this class must be part of some kind of security monitoring/advisory system (i.e. GLSA). Here's what I mean by all this:

Secure within its domain means that it only get those privileges absolutely necessary to its function- it should not have to run as root, for example. It should be possible to isolate the security level of any given software package, and should not run as a user account with an easy-to-crack password.

Dedicated to a function means it should not try to do it all- a DHCP server should manage IP addresses, not try to be a DNS, database, firewall, and desktop widget all at once.

Running lean and without bloat means it should only use necessary resources- no memory holes to speak of, no extra features or gui's, if possible.

Stable obviously means not prone to crashing.

Isolated from the OS meaning that, when it does crash, it doesn't take the whole server with it- if it must crash, it should only affect its own domain, which should be easy to sanitize without requiring a server reboot (Linux does this very well natively anyway).

Scalable is just what it means- deployable to a group of users as easily as to just one user.

As a Linux server, the basic type is LAMP, which are packages that have a strong reputation. How about additional functions that a LAMP cannot handle? How about network-level authentication? I have read about the Linux version of AD, but I am more curious abobut experiences with the associated packages, as well as security and functionality weaknesses, as well as potential security oversights. Any thoughts?

Thanks!



  reply	other threads:[~2008-09-30 18:10 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-09-30 17:36 [gentoo-server] Server Packages for Gentoo BRM
2008-09-30 18:10 ` Spahn, Daniel [this message]
2008-09-30 20:51 ` Ajai Khattri
  -- strict thread matches above, loose matches on Subject: below --
2008-10-01 14:51 BRM
2008-10-01 15:10 ` Arturo 'Buanzo' Busleiman
2008-10-01 13:16 BRM
2008-09-30 16:17 BRM
2008-09-30 17:28 ` Robert Bridge
2008-10-01 10:55   ` Kerin Millar
2008-10-01 14:34     ` Robert Bridge
2008-10-01 14:48       ` Spahn, Daniel
2008-10-01 15:23       ` Kerin Millar
2008-10-02  9:20       ` Pavel Labushev
2008-10-03 14:35       ` kashani
2008-09-30 14:43 BRM
2008-09-30 15:05 ` Graham Murray
2008-09-29 17:48 Spahn, Daniel
2008-09-30  8:28 ` Ramon van Alteren

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=BA4D8FC573225D4798B6569AAF63F6AD0209169679@OMAC-INEXMBX01.intranet.hdr \
    --to=dspahn@cuh2a.com \
    --cc=gentoo-server@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox