If config changes are difficult to someone, mabey they are not using the correct tools.(dispatch-conf)
I run an enterprise-level server and I love that Gentoo doesn't arbitrarily overwrite my configs. I really think that Gentoo correctly notifies you the admin that technology has changed (and is deprecated) rather than just going on and letting you think everything is peachy. If someone is using apache,php or ldap they SHOULD be editing these files and verifying there are no unauthorized/incorrect changes as well as keeping up to date with current features. As for kernel config I believe a minimalistic kernel reduces the chance for exploitation/system hangs.
If config changes are difficult to someone, mabey they are not using the correct tools.(dispatch-conf) I run an enterprise-level server and I love that Gentoo doesn't arbitrarily overwrite my configs. I really think that Gentoo correctly notifies you the admin that technology has changed (and is deprecated) rather than just going on and letting you think everything is peachy. If someone is using apache,php or ldap they SHOULD be editing these files and verifying there are no unauthorized/incorrect changes as well as keeping up to date with current features. As for kernel config I believe a minimalistic kernel reduces the chance for exploitation/system hangs.