[5597] in RedHat Linux List

home help back first fref pref prev next nref lref last post

Re: RedHat4.0 security

daemon@ATHENA.MIT.EDU (Alex Mottram)
Fri Nov 22 15:59:26 1996

Date: Fri, 22 Nov 1996 10:00:32 -0600 (CST)
From: Alex Mottram <alex@net-connect.net>
To: Erik Troan <ewt@redhat.com>
cc: redhat-list@redhat.com
In-Reply-To: <Pine.LNX.3.93.961121184224.21340A-100000@redhat.com>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com

On Thu, 21 Nov 1996, Erik Troan wrote:

> > PS Let's see how many suid-bit removals these discussions can cause :)
> 
> /usr/X11R6/bin/SuperProbe is number one
> 
> Erik

A suggestion for the "things to consider box."  How about an option in 
the setup program for different types of Network setups (and different 
levels of "security").  I.e:

Desktop Workstation - SUID anything you like.  Basically one or a few 
trusted users logging in at the console.

Networked Workstation - trim the sticky bits a bit.  rip a bunch of the 
finger, rsh, rexec junk out of inetd.conf.

Network Server - Only suid things that absolutely need to be (i.e. no
suid mount/umount, etc..

etc...


Personally, I feel that the machine is only as secure as the person who 
sets it up lets it be.  No matter what happens, I'm still going to rip 
the sticky bits off of nearly everything anyway.  :)

More things for the wishlist:

Non-X config tools. (aside from "bash" and "vi" :)  )
Config tool for inetd.conf.

Thanks!


--
  PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
  ________________________________________________________________________
  http://www.redhat.com/RedHat-FAQ   http://www.redhat.com/RedHat-Errata
  http://www.redhat.com/RedHat-Tips  http://www.redhat.com/mailing-lists
  ------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null


home help back first fref pref prev next nref lref last post