Red Hat ES3.0 Security

This is a discussion on Red Hat ES3.0 Security within the Linux Security forums, part of the System Security and Security Related category; Can someone advise if RH ES3.0 is secure enough out of the box to perform ecommerce function without being ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 03-30-2005
Chris Mewton
 
Posts: n/a
Default Red Hat ES3.0 Security

Can someone advise if RH ES3.0 is secure enough out of the box to
perform ecommerce function without being behind a seperate firewall?
I guess yes, but have been told no.
regards

Chris
Reply With Quote
  #2 (permalink)  
Old 03-30-2005
HansF
 
Posts: n/a
Default Re: Red Hat ES3.0 Security

On Wed, 30 Mar 2005 10:26:32 +0000, Chris Mewton wrote:

> Can someone advise if RH ES3.0 is secure enough out of the box to
> perform ecommerce function without being behind a seperate firewall?
> I guess yes, but have been told no.
> regards
>


Since there have been patches written to ES3; since patches continue to be
written; and since the statement implies that no one will be looking for
and applying patches; IMO, the answer is NO.
Reply With Quote
  #3 (permalink)  
Old 03-30-2005
Darko Gavrilovic
 
Posts: n/a
Default Re: Red Hat ES3.0 Security

HansF <News.Hans@telus.net> wrote in
news:pan.2005.03.30.12.17.35.393535@telus.net:

> On Wed, 30 Mar 2005 10:26:32 +0000, Chris Mewton wrote:
>
>> Can someone advise if RH ES3.0 is secure enough out of the box to
>> perform ecommerce function without being behind a seperate firewall?
>> I guess yes, but have been told no.
>> regards
>>

>
> Since there have been patches written to ES3; since patches continue
> to be written; and since the statement implies that no one will be
> looking for and applying patches; IMO, the answer is NO.


Hi. Other than patching, I think the OP is asking, can he/she assume that
the default setup as released by Red Hat is secure without him/her having
to go through the different settings and start hardening the security
settings.

I don't use RedHat, but I assume that at the very least you will have to
go through and start looking at the different services running and start
disabling what you don't need.

--
"Why do they call it rush hour when nothing moves?", Robin Williams
Reply With Quote
  #4 (permalink)  
Old 03-30-2005
HansF
 
Posts: n/a
Default Re: Red Hat ES3.0 Security

On Wed, 30 Mar 2005 06:05:42 -0600, Darko Gavrilovic wrote:


> Hi. Other than patching, I think the OP is asking, can he/she assume that
> the default setup as released by Red Hat is secure without him/her having
> to go through the different settings and start hardening the security
> settings.


Sorry, that's not the way I read it. But even if proper & regular
SysAdmin is involved, security still depends on how the system was
installed, what options were selected, etc.

While the RHEL3 default is pretty reasonable, I wouldn't put a credit-card
handling, billing, or company jewels system on an unhardened OS - of any
vintage. I'd suggest also reading thru the WROX press "Professional Red
Hat Enterprise Linux 3' Chapter 15 to help make the appropriate install
and setup decisions.

> I don't use RedHat, but I assume that at the very least you will have to
> go through and start looking at the different services running and start
> disabling what you don't need.


Yup. AND, I'd still recommend walking thru Bob Toxen's book "Real World
Linux Security"

/Hans
Reply With Quote
  #5 (permalink)  
Old 03-30-2005
Jason Bowen
 
Posts: n/a
Default Re: Red Hat ES3.0 Security

Chris Mewton wrote:
> Can someone advise if RH ES3.0 is secure enough out of the box to
> perform ecommerce function without being behind a seperate firewall?
> I guess yes, but have been told no.
> regards
>
> Chris


Security isn't as simplistic as you want it to be. The simple answer is
no, RHEL 3 has had many patches issued since it was first released.
What exactly would you be planning to do with your machine?
Reply With Quote
  #6 (permalink)  
Old 04-07-2005
Chris Mewton
 
Posts: n/a
Default Re: Red Hat ES3.0 Security

Many thanks for that informed discussion, and for the recommended
reading. My experience with redhat has remained in local networks and
so haven't had to get too involvolved with security.

My understandng of situation was that the OS would be patched to death
by the hosting company - Rackspace, but they recommended the use of a
hardware firewall which appeared to be prohibitively expensive
increasing the cost by nearly 50 percent. An option existed to run
without firewall but that would leave the burden of responisbility on my
narrow and feeble shoulders. So I wanted to get the facts.
Fact is I'll do some more reading, and in the mean time book space on a
secured server. thanks again for your input and that of Darko.
Regards

Chris

HansF wrote:
> On Wed, 30 Mar 2005 06:05:42 -0600, Darko Gavrilovic wrote:
>
>
>
>>Hi. Other than patching, I think the OP is asking, can he/she assume that
>>the default setup as released by Red Hat is secure without him/her having
>>to go through the different settings and start hardening the security
>>settings.

>
>
> Sorry, that's not the way I read it. But even if proper & regular
> SysAdmin is involved, security still depends on how the system was
> installed, what options were selected, etc.
>
> While the RHEL3 default is pretty reasonable, I wouldn't put a credit-card
> handling, billing, or company jewels system on an unhardened OS - of any
> vintage. I'd suggest also reading thru the WROX press "Professional Red
> Hat Enterprise Linux 3' Chapter 15 to help make the appropriate install
> and setup decisions.
>
>
>>I don't use RedHat, but I assume that at the very least you will have to
>>go through and start looking at the different services running and start
>>disabling what you don't need.

>
>
> Yup. AND, I'd still recommend walking thru Bob Toxen's book "Real World
> Linux Security"
>
> /Hans

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 04:24 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0