[644] in bugtraq
Re: secure www site FAQ ???
daemon@ATHENA.MIT.EDU (Mr Martin J Hargreaves)
Mon Jan 16 10:59:43 1995
Date: Mon, 16 Jan 1995 13:58:36 +0000 (GMT)
From: Mr Martin J Hargreaves <ch11mh@surrey.ac.uk>
To: Ron Steriti <steriti@donald.cpe.uml.edu>
Cc: bugtraq@fc.net
In-Reply-To: <3f1equ$5vm@ulowell.uml.edu>
On 11 Jan 1995, Ron Steriti wrote:
> Is there a FAQ describing how to set up a secure www site?
> (gopher, mosaic)
I just wrote up some HTML on the WWW site here, which is set up
quite securely. It's available at
http://www.chem.surrey.ac.uk/~ch11mh/secure.html
It consists basically of "Get a cheap single purpose machine with
a free OS, and disabled every subsystem you don't need (all but networking)
then run all the security tools you can find on it and check it every day"
I hope this is useful (a lot of questions regarding secure http
servers seem to have come up recently). This does not address encrypting
servers - I may do something on this later.
Regards,
M.
----------------------------------------------------------------
| Martin Hargreaves, ch11mh@surrey.ac.uk|
| Undergraduate Computational Chemist |
| WWW Server Admin http://www.chem.surrey.ac.uk|
----------------------------------------------------------------