View previous topic :: View next topic |
Author |
Message |
flipnode Apprentice


Joined: 03 Oct 2004 Posts: 172 Location: USA
|
Posted: Thu Mar 10, 2005 8:41 pm Post subject: Converted my Server to Gentoo! Server Security |
|
|
I have officially converted my FreeBSD system over to gentoo. I think this will be a good thing. System maintence is easier. Well, see how stable this will be. Anyone have any things I should do to make my gentoo system more secure? Also, if I have a hardware firewall... Do I need to run one on the server? It will be a webserver, sshd, ProFTP ,no telnet, no email server, no dhcp, no dns. I might hook samba up to it though.
thanks guys _________________ I think Gentoo is great! |
|
Back to top |
|
 |
hds Advocate


Joined: 21 Aug 2004 Posts: 2629 Location: Sprockhoevel [GER]
|
Posted: Thu Mar 10, 2005 8:45 pm Post subject: Re: Converted my Server to Gentoo! Server Security |
|
|
flipnode wrote: | Also, if I have a hardware firewall... Do I need to run one on the server? |
no. |
|
Back to top |
|
 |
flipnode Apprentice


Joined: 03 Oct 2004 Posts: 172 Location: USA
|
Posted: Fri Mar 11, 2005 9:22 am Post subject: Security Tip # 1 |
|
|
Okay, seeing how no one knows anything about security. I have a little basic security tip I found.
http://www.linuxplanet.com/linuxplanet/tips/1151/1/
more tips to come! _________________ I think Gentoo is great! |
|
Back to top |
|
 |
Nard` Apprentice

Joined: 23 Jan 2005 Posts: 250
|
Posted: Fri Mar 11, 2005 9:29 am Post subject: |
|
|
Some systems don't use inetd
You might want to investigate a replace for ProFTP, infact a replacement for FTP! maybye sftp? that depends what uses you have for it of course...
http://www.gentoo.org/doc/en/gentoo-security.xml is worth a read. Using public key authentication for sshd is a good thing.
If your reallly paranoid running webserver in a chroot or even uml is an option. reguarly updating is a good idea and you might want to use glsa-check, but that *IS* expiremental.
Securing gentoo is like securing most other *nix systems really. Audit SUID files, remove what you don't need, run anything possible as non-root, log, firewall, etc  _________________ Programming is the process of putting bugs in.
Debugging is the process of attempting to take bugs out, doing an ugly hack, hitting your computer, then claiming insurance. |
|
Back to top |
|
 |
flipnode Apprentice


Joined: 03 Oct 2004 Posts: 172 Location: USA
|
Posted: Sun Mar 13, 2005 9:41 am Post subject: |
|
|
Thanks for the info ..  _________________ I think Gentoo is great! |
|
Back to top |
|
 |
|