Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] server installation best practices/ worksheet
- Date: Sat, 26 May 2007 00:18:41 +0900
- From: Patrick Kellaher <kalmite@example.com>
- Subject: Re: [tlug] server installation best practices/ worksheet
- References: <4F9DBC6A-C926-4369-A9B0-05A2078F91CE@miyazaki-mic.ac.jp> <46528A96.6050903@gmo.jp> <979F1B40-7425-41B2-8E4E-0D49890697A5@miyazaki-mic.ac.jp> <46539705.1010601@gmo.jp> <4656ECBB.3060100@runbox.com>
- User-agent: Thunderbird 1.5.0.10 (X11/20070301)
Sigurd Urdahl wrote:
Parts of Erin's list is BP (best) at my work place, but some would be "bad practices". Not because they are bad, but because we have standardised on other ways of doing things.Both of these are no-no's in my department. It makes it easier to be on call sysadmin if we keep SSH at the standard port, and there have to be a very good reason for it if we expose that port to the internet. Allowing root logins also makes the on call sysadmin's job easier, we just try to change the passwords quite often. (we keep a secure password database, and we have different passwords for every security domain3.Disallow root log ons.[2] 4.Change SSH default port to something else.[2]
Just my 2 cents about #3, what dis-allowing root log ons does is create a fine grained audit trail. What to know which sysad logged in at a particular time and made that change that inadvertently killed something else? You will never know for sure if all the sysads log on with root. su and sudo add entries into the logs so you know who was doing what and when.
Now number 4 is a good idea to defend against automated attacks, but we all know that nmap does a very good job detecting what is running on a system.
Pat
- Follow-Ups:
- Re: [tlug] server installation best practices/ worksheet
- From: Godwin Stewart
- Re: [tlug] server installation best practices/ worksheet
- From: Stuart Luppescu
- References:
- [tlug] server installation best practices/ worksheet
- From: Micheal Cooper
- Re: [tlug] server installation best practices/ worksheet
- From: Erin D. Hughes
- Re: [tlug] server installation best practices/ worksheet
- From: Micheal Cooper
- Re: [tlug] server installation best practices/ worksheet
- From: Erin D. Hughes
- Re: [tlug] server installation best practices/ worksheet
- From: Sigurd Urdahl
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] ssh tunnel in background requires nohup?
- Next by Date: Re: [tlug] server installation best practices/ worksheet
- Previous by thread: Re: [tlug] server installation best practices/ worksheet
- Next by thread: Re: [tlug] server installation best practices/ worksheet
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links