Mailing List Archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [tlug] Unix's 40th Birthday



On 2009-08-22 00:18 +0900 (Sat), Edward Middleton wrote:

> Well if security is a priority over ease of use Hardened Gentoo offers
> a number of pretty good combinations. I have used PAX hardened SELinux
> installs on servers....

See my previous post for why SELinux is more likely, for most people, to
reduce than increase your security.

(How well have you audited your SELinux configuration?)

Speaking of security, is there some simple way to convince the linux
kernel to let a non-root application bind to a port under 1024? This
has been one of my biggest security nightmares when switching from BSD
to Linux: starting a lot of stuff as root when I didn't used to have to
do this. Currently I'm getting around this with a NAT translation, but
that's just one more thing to silently fail.

cjs
-- 
Curt Sampson       <cjs@example.com>        +81 90 7737 2974
           Functional programming in all senses of the word:
                   http://www.starling-software.com


Home | Main Index | Thread Index

Home Page Mailing List Linux and Japan TLUG Members Links