store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sat May 18, 2013 9:50 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 
Author Message
 Post subject: ASL manual
Unread postPosted: Tue Nov 28, 2006 6:57 pm 
Offline
New Forum User
New Forum User

Joined: Tue Nov 28, 2006 6:48 pm
Posts: 2
Hi all,
first of all thank to Scott and the others involved in this great stuff.

I was wondering, from a newbie point of view, how many things I have to manually tweak to get an ASL hardened system (centos 4 with plesk8) perfectly fitted to my needs.

Do you have any sort of checklist or manual or best policy to tell to each of the subscriber of ASL?

What do you suggest?

Thanks in advance.


Top
 Profile  
 
 Post subject:
Unread postPosted: Wed Nov 29, 2006 3:32 am 
Offline
Forum Regular
Forum Regular

Joined: Sat Aug 12, 2006 8:14 am
Posts: 117
hi,
yeah that would be great...

greets
zeki


Top
 Profile  
 
 Post subject:
Unread postPosted: Thu Nov 30, 2006 10:27 am 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
The manuals I would look at are the RHEL 4 SELinux documentation:
http://www.redhat.com/docs/manuals/ente ... nux-guide/
http://www.nsa.gov/selinux/info/docs.cfm

and the GRSEC docs
www.grsecurity.net/quickstart.pdf
http://www.grsecurity.net/wiki/index.php

Both systems are available in the ASL kernel, and have some extremely powerful security features. In the 2.6.18 kernel release Im working on right now, I'm planning on expanding the process ACL system in GRSEC to enforce much tighter controls on kernel modules, and the way the apache user can interact with the system, as well as include a basic "security posture" configuration module to give you feedback on what your security posture really is. Ideally I'd like to combine this with some basic auditing (ie, tell you safe_mode is on/off, scary php settings, etc) during the configuation mode. Last but not least, I want to get the Xen server virtualization system into 2.6.18.

mod_security is the other big component, and mike is working on getting the rules converted over to the 2.0 format. Once that is complete, we're planning on including a rule updater, and support for integration with our "known-attacker" RBL. Docs for mod_security are available here:
http://www.modsecurity.org/documentation/index.html


Top
 Profile  
 
 Post subject:
Unread postPosted: Thu Nov 30, 2006 12:12 pm 
Offline
New Forum User
New Forum User

Joined: Tue Nov 28, 2006 6:48 pm
Posts: 2
Thanks Scott, they are good reference.

But I was thinking of something more quick.
A quickreference where to go and check up the essential todo things.

Thanks however.


Top
 Profile  
 
 Post subject:
Unread postPosted: Thu Nov 30, 2006 2:06 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7418
Location: earth
As ASL stands today, you dont really need to do anything to get it going. It is configured with default security policies enabled. Those docs outline a lot of features that are in it, but not used at this time. Process ACL's, and RBAC for example.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group