Group: comp.os.linux.security


Subject: Security and manageability minded LiveCD?
From: s. keeling
Date: 11/15/2007 3:32:00 AM
lbrtchx@gmail.com <lbrtchx@gmail.com>: > > I am a LiveCD enthusiast who has been using kanotix, knoppix (since > its 3.8 version ;-)) and FreesBIE and I have been minding for some > time about using liveCD's as full blown servers > > There is little and spotty information on this. yeah! you could > certainly run apache right off your knoppix distro, but is this the > way you would actually run your server? Modern live cds will slurp themselves into RAM assuming you've enough to do it (.5 Gb). So, why not if you know how to control it? If you're remastering distros so your boots understand where and what they are when they boot, what's the diff from running from disk? Speed. Network latency may swamp that speed gain, but what the hey? As long as your installs know where their loghost is, where /var is, and how to talk dhcp (or static?), it should be great. Problem? Frob it. Still problem? Hardware! > Very little is mentioned, if at all, about OS hardening and > protection such as what you could achieve with open source grsecurity, > SELinux, PAX, ... Go to distrowatch.com and search distro types related to security. > Having something like a base-line sever liveCD that would let you > easily customize/remaster the rest to your liking would be superb! Sure. Lots of people suggest LFS/Linux From Scratch. I suggest you build it. With busybox and expect and all the other whiz-bang tools out there, it's really not that hard. You can even do it by pulling individual debs/rpms off an install CD and dumping them into a loop mounted iso filesystem. Throw something in there that gives it something to boot from, and burn it. I think I'd start pulling stuff off a Sidux live CD, myself. -- Any technology distinguishable from magic is insufficiently advanced. (*) http://blinkynet.net/comp/uip5.html Linux Counter #80292 - - http://www.faqs.org/rfcs/rfc1855.html Please, don't Cc: me.