P { MARGIN-BOTTOM: 0px; MARGIN-TOP: 0px }
Greetings,
I had a couple of questions about the direction the RHEL 7 SSG will be going;
Particularly with the below new subsystems in 7;
gconf vs dconf (GNOME 2 vs GNOME 3)
Has there been a decision on how to check and remediate with dconf? iptables vs firewalld
Has there been a decision on which method will go forward for check / remediation? chrony vs ntpd
Has there been a decision on which to use and which will go forward for check / remediation?
Thank you for your time,
-Nick
--
Nicholas P. Crawford
Senior UNIX Systems Administrator
contractor, General Dynamics Information Technology
NVESD Network Services Branch, US Army
email: Nicholas.Crawford@gdit.com
comm: (703) 704-2299 dsn: (312) 654-2299
cell: (571) 225-1283
On 10/3/14, 3:31 PM, Crawford, Nicholas P CTR USARMY CERDEC (US) wrote:
Greetings,
I had a couple of questions about the direction the RHEL 7 SSG will be going;
Particularly with the below new subsystems in 7;
gconf vs dconf (GNOME 2 vs GNOME 3)
Has there been a decision on how to check and remediate with dconf?iptables vs firewalld
Has there been a decision on which method will go forward forcheck / remediation? chrony vs ntpd
Has there been a decision on which to use and which will goforward for check / remediation?
Actually, there hasn't been much conversation on this. Thanks for starting the conversation!
IMO, we should start with system defaults as first/primary goal, then enable secondary configs in future passes. aka, address firewalld first then iptables.
If we're able to get both done at the same time, then great -- but focus should be on system default first.
What does everyone think of such an approach?
On Fri, Oct 3, 2014 at 5:08 PM, Shawn Wells shawn@redhat.com wrote:
On 10/3/14, 3:31 PM, Crawford, Nicholas P CTR USARMY CERDEC (US) wrote:
Greetings,
I had a couple of questions about the direction the RHEL 7 SSG will be going;
Particularly with the below new subsystems in 7;
gconf vs dconf (GNOME 2 vs GNOME 3)
Some applications do use gconf still, but I believe gnome requires dconf in RHEL7 since it is GNOME3. There is an existing pull request for converting most of the gconf settings to dconf.
Has there been a decision on how to check and remediate with dconf?iptables vs firewalld
iptables and firewalld conflict each other so one or the other (preferably firewalld).
Has there been a decision on which method will go forward forcheck / remediation? chrony vs ntpd
No decision has been made on this as I am aware.
Has there been a decision on which to use and which will goforward for check / remediation?
Actually, there hasn't been much conversation on this. Thanks for starting the conversation!
IMO, we should start with system defaults as first/primary goal, then enable secondary configs in future passes. aka, address firewalld first then iptables.
If we're able to get both done at the same time, then great -- but focus should be on system default first.
What does everyone think of such an approach?
+1
-- SCAP Security Guide mailing list scap-security-guide@lists.fedorahosted.org https://lists.fedorahosted.org/mailman/listinfo/scap-security-guide https://github.com/OpenSCAP/scap-security-guide/
P { MARGIN-BOTTOM: 0px; MARGIN-TOP: 0px }
Please excuse my OWA induced top post.
Thank you for the information.
I found the dconf pull request (#229 https://github.com/OpenSCAP/scap-security-guide/pull/229). Should discussion occur in the comments on github or on the list?
I'll start new threads to separate the discussion for chrony/ntp and iptables/firewalld.
-Nick
--
Nicholas P. Crawford
Senior UNIX Systems Administrator
contractor, General Dynamics Information Technology
NVESD Network Services Branch, US Army
email: Nicholas.Crawford@gdit.com
comm: (703) 704-2299 dsn: (312) 654-2299
cell: (571) 225-1283
From: scap-security-guide-bounces@lists.fedorahosted.org [scap-security-guide-bounces@lists.fedorahosted.org] on behalf of Gabe Alford [redhatrises@gmail.com] Sent: Saturday, October 04, 2014 12:43 To: SCAP Security Guide Subject: Re: RHEL 7 Direction
On Fri, Oct 3, 2014 at 5:08 PM, Shawn Wells shawn@redhat.com wrote:
On 10/3/14, 3:31 PM, Crawford, Nicholas P CTR USARMY CERDEC (US) wrote:
Greetings,
I had a couple of questions about the direction the RHEL 7 SSG will be going;
Particularly with the below new subsystems in 7;
gconf vs dconf (GNOME 2 vs GNOME 3)
Some applications do use gconf still, but I believe gnome requires dconf in RHEL7 since it is GNOME3. There is an existing pull request for converting most of the gconf settings to dconf.
Has there been a decision on how to check and remediate with dconf?iptables vs firewalld
iptables and firewalld conflict each other so one or the other (preferably firewalld).
Has there been a decision on which method will go forward forcheck / remediation? chrony vs ntpd
No decision has been made on this as I am aware.
Has there been a decision on which to use and which will goforward for check / remediation?
Actually, there hasn't been much conversation on this. Thanks for starting the conversation!
IMO, we should start with system defaults as first/primary goal, then enable secondary configs in future passes. aka, address firewalld first then iptables.
If we're able to get both done at the same time, then great -- but focus should be on system default first.
What does everyone think of such an approach?
+1
-- SCAP Security Guide mailing list scap-security-guide@lists.fedorahosted.org https://lists.fedorahosted.org/mailman/listinfo/scap-security-guide https://github.com/OpenSCAP/scap-security-guide/
----- Original Message -----
From: "Gabe Alford" redhatrises@gmail.com To: "SCAP Security Guide" scap-security-guide@lists.fedorahosted.org Sent: Saturday, October 4, 2014 6:43:24 PM Subject: Re: RHEL 7 Direction
On Fri, Oct 3, 2014 at 5:08 PM, Shawn Wells < shawn@redhat.com > wrote:
On 10/3/14, 3:31 PM, Crawford, Nicholas P CTR USARMY CERDEC (US) wrote:
Greetings,
I had a couple of questions about the direction the RHEL 7 SSG will be going;
Particularly with the below new subsystems in 7;
gconf vs dconf (GNOME 2 vs GNOME 3)
Some applications do use gconf still, but I believe gnome requires dconf in RHEL7 since it is GNOME3. There is an existing pull request for converting most of the gconf settings to dconf.
Has there been a decision on how to check and remediate with dconf? iptables vs firewalld
iptables and firewalld conflict each other so one or the other (preferably firewalld).
+1 for firewalld due to ability to apply changes runtime (without disrupting existing connections) + due to concept of zones: https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/htm...
Has there been a decision on which method will go forward for check / remediation? chrony vs ntpd
No decision has been made on this as I am aware.
Comparison why chronyd might be preferred before ntpd: https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/htm...
Has there been a decision on which to use and which will go forward for check / remediation?
Actually, there hasn't been much conversation on this. Thanks for starting the conversation!
IMO, we should start with system defaults as first/primary goal, then enable secondary configs in future passes. aka, address firewalld first then iptables.
If we're able to get both done at the same time, then great -- but focus should be on system default first.
What does everyone think of such an approach?
+1
Commented on this in previous post.
Thank you && Regards, Jan. -- Jan iankko Lieskovsky / Red Hat Security Technologies Team
Hmm, I remember being lambasted about not having NTP auth syncing enabled and chronyd doesn't appear to support this.
Thoughts?
Trevor
On Mon, Oct 6, 2014 at 12:09 PM, Jan Lieskovsky jlieskov@redhat.com wrote:
----- Original Message -----
From: "Gabe Alford" redhatrises@gmail.com To: "SCAP Security Guide" scap-security-guide@lists.fedorahosted.org Sent: Saturday, October 4, 2014 6:43:24 PM Subject: Re: RHEL 7 Direction
On Fri, Oct 3, 2014 at 5:08 PM, Shawn Wells < shawn@redhat.com > wrote:
On 10/3/14, 3:31 PM, Crawford, Nicholas P CTR USARMY CERDEC (US) wrote:
Greetings,
I had a couple of questions about the direction the RHEL 7 SSG will be going;
Particularly with the below new subsystems in 7;
gconf vs dconf (GNOME 2 vs GNOME 3)
Some applications do use gconf still, but I believe gnome requires dconf
in
RHEL7 since it is GNOME3. There is an existing pull request for
converting
most of the gconf settings to dconf.
Has there been a decision on how to check and remediate with dconf? iptables vs firewalld
iptables and firewalld conflict each other so one or the other
(preferably
firewalld).
+1 for firewalld due to ability to apply changes runtime (without disrupting existing connections) + due to concept of zones:
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/htm...
Has there been a decision on which method will go forward for check / remediation? chrony vs ntpd
No decision has been made on this as I am aware.
Comparison why chronyd might be preferred before ntpd:
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/htm...
Has there been a decision on which to use and which will go forward for check / remediation?
Actually, there hasn't been much conversation on this. Thanks for starting the conversation!
IMO, we should start with system defaults as first/primary goal, then enable secondary configs in future passes. aka, address firewalld first then iptables.
If we're able to get both done at the same time, then great -- but focus should be on system default first.
What does everyone think of such an approach?
+1
Commented on this in previous post.
Thank you && Regards, Jan.
Jan iankko Lieskovsky / Red Hat Security Technologies Team
SCAP Security Guide mailing list scap-security-guide@lists.fedorahosted.org https://lists.fedorahosted.org/mailman/listinfo/scap-security-guide https://github.com/OpenSCAP/scap-security-guide/
----- Original Message -----
From: "Shawn Wells" shawn@redhat.com To: scap-security-guide@lists.fedorahosted.org Sent: Saturday, October 4, 2014 1:08:55 AM Subject: Re: RHEL 7 Direction
On 10/3/14, 3:31 PM, Crawford, Nicholas P CTR USARMY CERDEC (US) wrote:
Greetings,
I had a couple of questions about the direction the RHEL 7 SSG will be going;
Particularly with the below new subsystems in 7;
gconf vs dconf (GNOME 2 vs GNOME 3)
Has there been a decision on how to check and remediate with dconf?iptables vs firewalld
Has there been a decision on which method will go forward forcheck / remediation? chrony vs ntpd
Has there been a decision on which to use and which will goforward for check / remediation?
Actually, there hasn't been much conversation on this. Thanks for starting the conversation!
IMO, we should start with system defaults as first/primary goal, then enable secondary configs in future passes. aka, address firewalld first then iptables.
If we're able to get both done at the same time, then great -- but focus should be on system default first.
What does everyone think of such an approach?
+1 on this approach (on preferring the default packages / services in new RHEL-7 release than staying on the recommendations for the old[er] version).
Three aspects behind this reasoning: * SSG users accustomed to use SSG guidance for old(er) RHEL versions might be actually more familiar how to (securely) use packages / services, that were default in the old(er) RHEL versions. But where they are actually searching guidance from us is how to securely configure these new defaults,
* it should be kept in mind that RHEL-7 content evolved from RHEL-6 content (as a copy), while RHEL-7 as a product evolved from the engineering / developer effort from Fedora releases released into production between RHEL-6 & RHEL-7 products. Therefore as such there's a natural gap / discrepancy (current RHEL-7 content missing that evolution, reflections & corresponding discussion that actually led Fedora / upstream developers to change these defaults),
* due to maintenance reasons it's not good to stay / continue to rely on old(er) RHEL product defaults. While it might be possible to overcome the maintenance burden related with this in short time, it's not definitely a viable longterm support solution.
Thank you && Regards, Jan. -- Jan iankko Lieskovsky / Red Hat Security Technologies Team
-- SCAP Security Guide mailing list scap-security-guide@lists.fedorahosted.org https://lists.fedorahosted.org/mailman/listinfo/scap-security-guide https://github.com/OpenSCAP/scap-security-guide/
scap-security-guide@lists.fedorahosted.org