This is a discussion on Software within the Linux Security forums, part of the System Security and Security Related category; I would say that using DTE would be one of the best methods of locking down a server. Let me ...
|
|||||||
| FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
|
|||
|
I would say that using DTE would be one of the best methods of locking down a server.
Let me explain, with DTE (as Palante's Defcon server uses ((was voted best server for a couple years in a row)), you can initialize compartments..I wont go in depth, but even the NSA's Linux Mods aint got nuttin on this bad boy.. DTE = Domain Type Enforcement, basically once your all done with this, root is basically just a 'regular' user, even with full permissions, root couldnt even rm his own files let alone anything on a DTE server ..we you figure it out..any question let me know, i can provide some insight to this. |