From: "Walter Dnes" <waltdnes@waltdnes.org>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] root password gremlin
Date: Sun, 20 Nov 2005 00:57:44 -0500 [thread overview]
Message-ID: <20051120055744.GC4003@waltdnes.org> (raw)
In-Reply-To: <4529AEC8-F16F-4D44-8DDA-AE9347619E27@jolet.net>
On Sat, Nov 19, 2005 at 06:51:36AM -0600, John Jolet wrote
> On Nov 19, 2005, at 12:39 AM, Alexander Skwar wrote:
> >What do you need PAM for, when there's basically just one
> >(human) user on the system and the system acts as a "consumer"
> >(ie. no servers)? Why add the complexity of PAM? Where's
> >the gain - in *THAT* scenario?
>
> I'm not sure about you, but I can think of MANY times over my career
> when I set up a box "to do just one thing" or "for just one person"
> and down the road all of a sudden, I needed another thing or another
> person. Retrofitting pam onto a running, configured system is not
> something I'd care to attempt. Having pam on from the beginning,
> if you don't fiddle with the defaults, poses no extra complexity.
> But then, I'm a belt and suspenders man.
This is my personal home machine. I'm the only user on it. I do not
run publicly visible servers. I've set iptables to block incoming
connections, excepting a small hole for my backup machine (6-year-old
Dell) so I can ssh/scp backups back and forth. I've also set my ADSL
modem/router to block *ALL* incoming connections, and *ALL* external
inbound traffic to ports 0..1023.
My ISP allows externally visible servers, but I haven't bothered to do
so. It's also conventional wisdom that you do *NOT* mix server apps and
a standard desktop on the same machine. If I ever do decide to run a
publicly-visible server, I'll get a used machine and run it on that, and
configure that machine from the ground up as a server. There are still
2 free ethernet ports on the back of my ADSL router/modem.
--
Walter Dnes <waltdnes@waltdnes.org> In linux /sbin/init is Job #1
My musings on technology and security at http://tech_sec.blog.ca
--
gentoo-user@gentoo.org mailing list
next prev parent reply other threads:[~2005-11-20 6:05 UTC|newest]
Thread overview: 53+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-11-17 19:17 [gentoo-user] root password gremlin ÿffffc1lvaro Castro
2005-11-17 19:22 ` Michael Sullivan
2005-11-17 19:37 ` ÿffffc1lvaro Castro
2005-11-17 19:37 ` Michael Kjorling
2005-11-17 19:44 ` Arturo 'Buanzo' Busleiman
2005-11-17 20:33 ` ÿffffc1lvaro Castro
2005-11-17 20:50 ` Arturo 'Buanzo' Busleiman
2005-11-17 21:58 ` ÿffffc1lvaro Castro
2005-11-17 22:04 ` Arturo 'Buanzo' Busleiman
2005-11-17 22:44 ` Neil Bothwick
2005-11-19 5:44 ` Walter Dnes
2005-11-17 23:11 ` Willie Wong
2005-11-19 5:45 ` Walter Dnes
2005-11-19 5:57 ` Patrick McLean
2005-11-19 6:39 ` Alexander Skwar
2005-11-19 12:07 ` Holly Bostick
2005-11-19 12:51 ` John Jolet
2005-11-20 5:57 ` Walter Dnes [this message]
2005-11-20 11:15 ` Alexander Skwar
2005-11-19 15:10 ` Arturo 'Buanzo' Busleiman
2005-11-19 17:50 ` abhay
2005-11-20 0:48 ` Arturo 'Buanzo' Busleiman
2005-11-20 1:43 ` Holly Bostick
2005-11-20 11:38 ` Arturo 'Buanzo' Busleiman
2005-11-20 11:32 ` Alexander Skwar
2005-11-20 11:46 ` Arturo 'Buanzo' Busleiman
2005-11-20 12:54 ` Alexander Skwar
2005-11-20 13:00 ` Arturo 'Buanzo' Busleiman
2005-11-20 13:13 ` Alexander Skwar
2005-11-20 13:26 ` Arturo 'Buanzo' Busleiman
2005-11-20 13:40 ` Alexander Skwar
2005-11-20 13:47 ` Arturo 'Buanzo' Busleiman
2005-11-20 13:46 ` Holly Bostick
2005-11-20 13:53 ` Arturo 'Buanzo' Busleiman
2005-11-20 14:36 ` Holly Bostick
2005-11-20 14:44 ` Arturo 'Buanzo' Busleiman
2005-11-20 18:07 ` kashani
2005-11-21 22:14 ` Abhay Kedia
2005-11-21 22:53 ` Holly Bostick
2005-11-22 12:58 ` Abhay Kedia
2005-11-20 13:00 ` [gentoo-user] regarding PAM [WAS: root password gremlin] Arturo 'Buanzo' Busleiman
2005-11-20 13:14 ` Alexander Skwar
2005-11-20 13:24 ` Arturo 'Buanzo' Busleiman
2005-11-20 13:38 ` Alexander Skwar
2005-11-20 13:49 ` Arturo 'Buanzo' Busleiman
2005-11-20 14:51 ` Alexander Skwar
2005-11-20 14:59 ` Arturo 'Buanzo' Busleiman
2005-11-20 15:24 ` Hemmann, Volker Armin
2005-11-20 17:50 ` Jerry McBride
2005-11-20 5:58 ` [gentoo-user] root password gremlin Walter Dnes
2005-11-20 11:27 ` Alexander Skwar
2005-11-20 12:04 ` [gentoo-user] " Francesco Talamona
2005-11-20 12:57 ` Alexander Skwar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20051120055744.GC4003@waltdnes.org \
--to=waltdnes@waltdnes.org \
--cc=gentoo-user@lists.gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox