EnGarde Secure Linux v2 Out
Chuck writes "I came across EnGarde Secure Linux about two years ago when it was first released, and I see they just released the newest version. Improved Mandatory Access Control using LIDS, awesome web-based manager, code from the Openwall Project and winner of the Network Computing Hardened Linux product of the year. I love EnGarde."
I thoght EnGarde was strictly commercial nowadays?? No?
Oh Engarde Linux,
We stand on guard for thee...
Anyway, LIDS is great. Played with it, and deemed it cool. Now I wish FreeBSD had something that cool (since that's my main OS of choice), but LOMAC comes pretty close.
Heck, I just might give this a whirl on one of my testboxes...
We like Astaro a lot.
& la ng=gb
http://www.astaro.de/php/statics.php?action=asl
Could anyone compare the 2?
Quoth the poster: "I love EnGarde."
The best part: it automatically uses protection! Just don't try a backdoor!
---OWWW! Stop hitting me!---
If a man's character is to be abused there's nobody like a relative to do the business. -Thackeray, William
Isn't this kinda risky? Shouldn't they have waited to see what happens with SCO first?
n00b alert. ok i understand the need for a secure platform like this one, but why are there so many different distros out. wouldn't it be more competitve to merge certain distros?
Ninnle Linux is the current gold standard for system and network security. I don't understand why people keep reinventing the wheel.
HUH? This is supposed to be an uber-secure system and you don't have to administer it? Somebody explain this to me like I'm a two year old, because I just don't get it.
How am I supposed to fit a pithy, relevant quote into 120 characters?
I hope these guys do some co-operation with thingies like OpenBSD. I would love to see outcome of that. Great!
RSBAC is, in many ways superior to LIDS.
I urge people who have tried, or interested in trying LIDS/SELinux, to give rsbac a go.
Available at rsbac.org
Buh? So what?
It's not a security problem...
Offtopic, but along the same vein, I would like to find a distribution of linux or *bsd that provides out of the box support for virtual mail hosting (many domains, 1 ip), name based virtual hosting, and the like. All with a simple to use console configuration. I've built my own several times, but thats time consuming. Anyone got any suggestions?
Tis better to be silent and thought a fool, than to open your mouth and remove all doubt --Abraham Lincoln
You had me going with improved MAC but threw me off with the web based manager. Web Based interfaces to security products feel very very wrong. I guess they can be done safely if only listening to loopback and using https.
Engarde comes in two flavors: commercial and community. Community is the free version.
Let's see how this baby performs against a Distributed Denial of Service attack....
[100% ISO 646 Compliant]
SVM, ERGO MONSTRO.
What? You decided not to implement because it requires you to configure it? And if you don't, it gives a benign error?
(Link points at an advisory stating that log check emails will bounce by default if not configured)
Skivvy Niner? Email me!
HEY! Look left just ONE MORE TIME!
as
which, I personally feel would be an interesting name for a security enhancing project - right up there with Big Brother.
ENOCAFFINE
www.eFax.com are spammers
OpenBSD lite. For the only interested in a partial code review...
Q. What is Calvin's monster snowman called? A. The Torment Of Existence Weighed Against The Horror of Non Being
Err. That's probably the mildest bug/security problem I've ever seen. Care to explain me what is the problem of either
- applying the update ?
- running the initial configuration process ?
Or were you simply googling for a defect to post and that's the ony one you found ?
Well my name is Dr. Richard Daystrom and I'm working on the M5 advanced protocol unit, the most ambitious computer ever made.
Of course, if you have an A7 computer classiciation you already know all this.
beware the goatse.cx link in the parent.
-- derby
Because there are too many distros and add-ons!
....but never mind. Survival of the fittest means that eventally MOST of us (and most Linux add-ons) will ultimately starve and die off.
Linux is in danger of losing direction much as UNIX did 20 years ago! Everyone can and does write Yet Another Add-On:
"Yaooooooooooo! I'm going to be rich!"
And they do this before they learn what is already out there, identify the good and bad parts (PROPERLY), and document what makes their solution worth the effort.
Properly: It is amazing how many people are willing to "take a look at" something and consider themselves versed enough to criticize! Most of the time, they are just criticizing the default UI and the way it installs!
Without the discipline of identifying and documenting the ideas that make a product unique, we're all just pzzzing in the wind!
Without some form of Intellectual Property protection, there is no money to pay for the analysis that MUST proceed real progress.
I foolishly dream of the world in which we can pursue our ideas without bloodlust and the ripping and gnashing of teeth!
Nah! It's so much more fun being so sure of ourselves and blaming our failures on everybody else. That's the way, right?
What's this supposed to be?
Is this such a big fat hairy deal that you have to charge a minimum of 800$ for a "oh-so-extra-special-secure-Linux" distro?
Ok, if it's so easy to install that any Webdesigner could get it on right out of the box I say ok, let them Dreamweavers pay the price if they're to cheap for hiring a sysadmin to their team.
But I seriously doupt that this one pulls the trick better than a securepatched SuSE, Debian or OpenBSD.
Does anybody have solid expierience with this distro and can they testify that its bizar retail price is justified?
We suffer more in our imagination than in reality. - Seneca
Ah, so these are the people OpenBSD learned everything from, right?
"turning it into a secure pubic server"
That's truly a noble endeavor... From my experience, most insecure pubic servers are loaded with viruses and trojans.
Even if a man chops off your hand with a sword, you still have two nice, sharp bones to stick in his eyes.
"Improved Mandatory Access Control" would be iMAC ?
Ninnle Linux does that.
Is there anyone out there that uses EnGarde in their production environment?
Domains for only $8.75/year! Transfer your domain for on
Solar Designer sues EnGarde Linux for alleged
intellectual property theft.
and our headline today...
SCO sues Solar Designer of Openwall and his ISP, the russian Dataforce, for alleged intellectual property theft, as they claim to own the source code and the tradmark of IP-suing cases.
The installation howto for LIDS says that you can turn it off by appending security=0 as a kernel parameter in your boot loader. This seems silly since they go to a lot of trouble to ensure that even the root user can't kill its processess and stuff. What is stopping the root user from just editing the boot loader conf and rebooting with these parameters.
Looks to me like it was mis-marked. It's a bugfix advisory only.