login
Header Space

 
 

Re: hardening BSD (was systrace/stsh policies)

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Date: Monday, October 15, 2007 - 10:30 pm

Aaron wrote:
    Thanks to everyone for answering/explaining what i know is in no way 
an easy question to answer with really an infinite number of answers 
depending on the skill set of the person answering and also the level of 
the person asking.  Like I said originally I'm fairly new to Openbsd, 
and to be honest, when i read that securelevels was able to be defeated 
and to move to systrace, i was a little overwhelmed reading up on it and 
looking at the examples.  The types of machines I will be running (when 
i feel comfortable enough with openbsd)(and am concerned about 
protecting, should i be more concerned about protecting my OBSD 
workstation too?  I run pf and only allow pass out w/return traffic 
allowed, no services at all) will be single or dual purpose servers.. 
i.e. http, smtp, imap etc, not machines that are running X and all my 
fav ports like amule (not that i would ever download anything from there 
anyway, that's just not safe :-)) I don't allow remote logins even via 
ssh except for the local networks, I always have a firewall in front of 
my public servers with rate limits (overload for pf fans) and I had  
decided a while back i was going to forgo the new bells and whistles in 
the latest and greatest versions of software, due to 
simplicity/security's sake. and only  run packages for the services I 
need, even though often times i get frustrated that things don't get 
brought current with every new release (i.e. hylafax or dspam).  _NOT 
COMPLAINING_, just giving an example. 
    Maybe it's good that these things came up with securelevels and 
systrace because to be honest , I'm not sure I would have been up for 
upgrading like I should with securelevels and i _know_ I would had a fit 
trying to get systrace policies set up, if not worse thinking i had them 
set up right and figuring out later they weren't and i had in fact 
lessened the security by putting all my trust in that system, at least 
at this point in my experience. From what I have comprehended both of 
the security mechanisms that have been "broken" still need to have 
someone that has gained root on the box (not that my understanding might 
not be flawed), which is one of the things that OpenBSD strives to disallow.
    For now I think I'll stick with the minimalistic type install, 
choosing software with a good security history, doing my best to 
configure things as safe (chrooting, using login.conf, running things as 
non-privileged users, etc...) as possible, as people have suggested, 
sticking with the openbsd package system and keeping a close eye on the 
systems via some of the suggestions made in this thread and in others on 
this list.  Perhaps by the time systrace is fixed or the next mechanism 
for securing beyond default install and common sense, if the teams 
decides to go the fixing systrace route, I'll be better prepared to 
utilize those tools.
    Thanks to the OpenBSD team for all the work and help.

Aaron
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
systrace/stsh policies, Xavier Mertens, (Thu Oct 11, 2:54 pm)
Re: systrace/stsh policies, Joachim Schipper, (Thu Oct 11, 6:05 pm)
hardening BSD (was systrace/stsh policies), Aaron, (Sun Oct 14, 4:27 pm)
Re: hardening BSD (was systrace/stsh policies), Aaron, (Mon Oct 15, 10:30 pm)
Re: hardening BSD (was systrace/stsh policies), Joachim Schipper, (Wed Oct 17, 3:15 pm)
Re: hardening BSD (was systrace/stsh policies) , Theo de Raadt, (Wed Oct 17, 3:28 pm)
Re: hardening BSD (was systrace/stsh policies), Joachim Schipper, (Mon Oct 15, 4:10 pm)
Re: hardening BSD (was systrace/stsh policies), Francesco Toscan, (Mon Oct 15, 2:31 am)
Re: hardening BSD (was systrace/stsh policies), Steve Shockley, (Sun Oct 14, 11:40 pm)
Re: hardening BSD (was systrace/stsh policies), Ted Unangst, (Mon Oct 15, 1:54 pm)
Re: hardening BSD (was systrace/stsh policies), Eduardo Tongson, (Mon Oct 15, 2:32 am)
Re: hardening BSD (was systrace/stsh policies), Janne Johansson, (Mon Oct 15, 11:46 am)
Re: hardening BSD (was systrace/stsh policies), Nick Guenther, (Mon Oct 15, 11:37 am)
Re: hardening BSD (was systrace/stsh policies), Darren Spruell, (Sun Oct 14, 5:07 pm)
speck-geostationary