cacert-sysadm AT lists.cacert.org
Subject: CAcert System Admins discussion list
List archive
- From: Mendel Mobach <cacert AT leercoden.nl>
- To: "Ian G (Audit)" <iang AT cacert.org>
- Cc: CAcert System Administrators <cacert-sysadm AT lists.cacert.org>
- Subject: Re: [Cacert-sysadm] Objections to a possible setup
- Date: Thu, 26 Mar 2009 21:13:45 +0100
On Mar 26, 2009, at 8:50 PM, Ian G (Audit) wrote:
On 25/3/09 22:46, Mendel Mobach wrote:
Hello everybody,
does someone on this list have sufficient technical objections against
the following setup:
Maybe I read this too quickly, but I was unable to figure out what the purpose of the setup is.
There are multi purposes here:
For the bigger picture:
* Create real virtual machines so we can move them 'easy' if we switch hardware.
* Create a scalable setup without too much changes from the current setup.
* Prepare for the future. IPv6, diffent security level networks, etc...
For instant 'now':
* Provide a more secure way of knowing who is logging in and is doing what on what server
(Yes nobody can tell who did what on what server, which is definitely bad!).
* Decrease the usage of (breakable) passwords
* Store some logging
(Debug logs from every kernel are probably not interresting)
( Security being of course very integrated with and dependent on the application, without an application it is perfectly secure :)
remote root access. And for once: Let's keep the hardware separated from the 'users'.
And if the setup proofs to be sufficient and easy enough we could use maybe for other services.
That's *not* a problem we need to fix right now, other services do log.
http://wiki.cacert.org/wiki/SecurityManual#Logging does request this kind of service for example.
Kind Regards,
Mendel Mobach
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
- [Cacert-sysadm] Objections to a possible setup, Mendel Mobach, 03/25/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Sam Johnston, 03/25/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Mendel Mobach, 03/25/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Mendel Mobach, 03/25/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Sam Johnston, 03/25/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Mendel Mobach, 03/25/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Mendel Mobach, 03/25/2009
- Re: [Cacert-sysadm] no Objections to a possible setup, Daniel Black, 03/25/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Ian G (Audit), 03/26/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Mendel Mobach, 03/26/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Ian G (Audit), 03/26/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Mendel Mobach, 03/26/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Ian G (Audit), 03/26/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Mendel Mobach, 03/26/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Ian G (Audit), 03/26/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Mendel Mobach, 03/27/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Wytze van der Raay, 03/27/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Mendel Mobach, 03/26/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Philipp Gühring, 03/27/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Ian G (Audit), 03/26/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Mendel Mobach, 03/26/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Ian G (Audit), 03/26/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Mendel Mobach, 03/26/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Sam Johnston, 03/25/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Mendel Mobach, 03/27/2009
- Re: [Cacert-sysadm] Objections to a possible setup, Philipp Guehring, 03/27/2009
Archive powered by MHonArc 2.6.16.