public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
From: "Walter Dnes" <waltdnes@waltdnes.org>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] root password gremlin
Date: Sun, 20 Nov 2005 00:57:44 -0500	[thread overview]
Message-ID: <20051120055744.GC4003@waltdnes.org> (raw)
In-Reply-To: <4529AEC8-F16F-4D44-8DDA-AE9347619E27@jolet.net>

On Sat, Nov 19, 2005 at 06:51:36AM -0600, John Jolet wrote

> On Nov 19, 2005, at 12:39 AM, Alexander Skwar wrote:

> >What do you need PAM for, when there's basically just one
> >(human) user on the system and the system acts as a "consumer"
> >(ie. no servers)? Why add the complexity of PAM? Where's
> >the gain - in *THAT* scenario?
> 
> I'm not sure about you, but I can think of MANY times over my career
> when I set up a box "to do just one thing" or "for just one person"
> and down the road all of a sudden, I needed another thing or another
> person.  Retrofitting pam onto a running, configured system is not
> something I'd care to attempt.  Having pam on from the beginning,
> if you don't fiddle with the defaults, poses no extra complexity.
> But then, I'm a belt and suspenders man.

  This is my personal home machine.  I'm the only user on it.  I do not
run publicly visible servers.  I've set iptables to block incoming
connections, excepting a small hole for my backup machine (6-year-old
Dell) so I can ssh/scp backups back and forth.  I've also set my ADSL
modem/router to block *ALL* incoming connections, and *ALL* external
inbound traffic to ports 0..1023.

  My ISP allows externally visible servers, but I haven't bothered to do
so.  It's also conventional wisdom that you do *NOT* mix server apps and
a standard desktop on the same machine.  If I ever do decide to run a
publicly-visible server, I'll get a used machine and run it on that, and
configure that machine from the ground up as a server.  There are still
2 free ethernet ports on the back of my ADSL router/modem.

-- 
Walter Dnes <waltdnes@waltdnes.org> In linux /sbin/init is Job #1
My musings on technology and security at http://tech_sec.blog.ca
-- 
gentoo-user@gentoo.org mailing list



  reply	other threads:[~2005-11-20  6:05 UTC|newest]

Thread overview: 53+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-11-17 19:17 [gentoo-user] root password gremlin ÿffffc1lvaro Castro
2005-11-17 19:22 ` Michael Sullivan
2005-11-17 19:37   ` ÿffffc1lvaro Castro
2005-11-17 19:37 ` Michael Kjorling
2005-11-17 19:44   ` Arturo 'Buanzo' Busleiman
2005-11-17 20:33   ` ÿffffc1lvaro Castro
2005-11-17 20:50     ` Arturo 'Buanzo' Busleiman
2005-11-17 21:58       ` ÿffffc1lvaro Castro
2005-11-17 22:04         ` Arturo 'Buanzo' Busleiman
2005-11-17 22:44         ` Neil Bothwick
2005-11-19  5:44         ` Walter Dnes
2005-11-17 23:11       ` Willie Wong
2005-11-19  5:45         ` Walter Dnes
2005-11-19  5:57           ` Patrick McLean
2005-11-19  6:39             ` Alexander Skwar
2005-11-19 12:07               ` Holly Bostick
2005-11-19 12:51               ` John Jolet
2005-11-20  5:57                 ` Walter Dnes [this message]
2005-11-20 11:15                 ` Alexander Skwar
2005-11-19 15:10               ` Arturo 'Buanzo' Busleiman
2005-11-19 17:50                 ` abhay
2005-11-20  0:48                   ` Arturo 'Buanzo' Busleiman
2005-11-20  1:43                     ` Holly Bostick
2005-11-20 11:38                       ` Arturo 'Buanzo' Busleiman
2005-11-20 11:32                     ` Alexander Skwar
2005-11-20 11:46                       ` Arturo 'Buanzo' Busleiman
2005-11-20 12:54                         ` Alexander Skwar
2005-11-20 13:00                           ` Arturo 'Buanzo' Busleiman
2005-11-20 13:13                             ` Alexander Skwar
2005-11-20 13:26                               ` Arturo 'Buanzo' Busleiman
2005-11-20 13:40                                 ` Alexander Skwar
2005-11-20 13:47                                   ` Arturo 'Buanzo' Busleiman
2005-11-20 13:46                                 ` Holly Bostick
2005-11-20 13:53                                   ` Arturo 'Buanzo' Busleiman
2005-11-20 14:36                                     ` Holly Bostick
2005-11-20 14:44                                       ` Arturo 'Buanzo' Busleiman
2005-11-20 18:07                                         ` kashani
2005-11-21 22:14                                   ` Abhay Kedia
2005-11-21 22:53                                     ` Holly Bostick
2005-11-22 12:58                                       ` Abhay Kedia
2005-11-20 13:00                           ` [gentoo-user] regarding PAM [WAS: root password gremlin] Arturo 'Buanzo' Busleiman
2005-11-20 13:14                             ` Alexander Skwar
2005-11-20 13:24                               ` Arturo 'Buanzo' Busleiman
2005-11-20 13:38                                 ` Alexander Skwar
2005-11-20 13:49                                   ` Arturo 'Buanzo' Busleiman
2005-11-20 14:51                                     ` Alexander Skwar
2005-11-20 14:59                                       ` Arturo 'Buanzo' Busleiman
2005-11-20 15:24                                     ` Hemmann, Volker Armin
2005-11-20 17:50                                       ` Jerry McBride
2005-11-20  5:58                 ` [gentoo-user] root password gremlin Walter Dnes
2005-11-20 11:27                 ` Alexander Skwar
2005-11-20 12:04                   ` [gentoo-user] " Francesco Talamona
2005-11-20 12:57                     ` Alexander Skwar

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20051120055744.GC4003@waltdnes.org \
    --to=waltdnes@waltdnes.org \
    --cc=gentoo-user@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox