Fedora default services (was: Re: F15 Feature - convert as many service init files as possible to the native SystemD services)

Chris Adams cmadams at hiwaay.net
Tue Dec 7 02:08:49 UTC 2010


Once upon a time, Adam Williamson <awilliam at redhat.com> said:
> On most laptops, however, which are the most common types of system sold
> today, a firewall is very definitely needed when you're connecting to
> hotel networks, public wifi access points...

The only thing you need a firewall by default for is to prevent services
that are listening on the network from being accessible.  The better
solution is to stop having services listen on the network by default.

This was done for sendmail many years ago; why hasn't it been done for
other things, such as rpcbind (and RPC services), cups, etc.?  These
daemons should bind to localhost only unless otherwise configured.

-- 
Chris Adams <cmadams at hiwaay.net>
Systems and Network Administrator - HiWAAY Internet Services
I don't speak for anybody but myself - that's enough trouble.


More information about the devel mailing list