Hi Pascal,
On Fri, Mar 18, 2005 at 09:27:40AM +0100, Pascal Steichen wrote:
As most of you might know I'm working at the
mineco where we have a very
nice project called CASES (
http://www.cases.lu/) about awarenesss
raising
in IT security.
Who exactly is the target public?
end-users, SMEs and administrations ...
We want to be vendor independant (legal
obligation as
government) and as such attach our best practices with "real life"
examples. However at the moment we only have the M$ world represented
(see
http://www.cases.public.lu/pratique/solutions/index.html) still seeking
for people providing use with screenshot procedures from the GNU/Linux
world.
I guess there are less security concerns with FOSS ;-)
well... I won't argue here ;)
From what I
read there, it looks like this is end-user or possibly
SME oriented?
For this we thought of using SUSE and a Fedora as
model GNU/Linux
systems.
So, what you'd expect is guides on how to keep the system updated
and how to configure a simple firewall on these systems?
I personally can't think of much else for a desktop usage of
GNU/Linux systems, OTOH it might be "too much" to put up NSA-style
guides (which really are useful) on how to really lock down server
platforms...
Would a "simple" guide on how to secure a GNU/Linux server be
of interest? Best practices, ... Idem for networking stuff...?
well if your are interessted (Linuxdays ?) we might define the scope more
clearly, at the moment we have the M$ examples and would like to have a
counter-weight to that in the FLOSS world ;)
If anyone (or his company) here on the list would
be interessted to do
this job, we would be very glad ;)
N.B.: However this will be a no-remuneration job,
all we can provide is
"advertising" via a CASES-partner thing ! So if one could do this on
behalf of LiLux it would be great, cause then we (LiLux) would be linked
on one of the biggest gov sites here in Lux ;)
:-)
My problem is that I'm not currently using the "target" distros...
otherwise it would be a simple thing to get a few screenshots plus
explanations done.
Hope you could tease some of you and I'm
looking forward for proposals
;)
If you have some other concrete ideas, bring them up, I'm sure we
can work some stuff out.
well it's relatively open but should cover the mostly only the basics, the
server idea thing is not however bad as more and more SMEs get FLOSS
servers (firewalls) ...
Eric
Byetheway in the same project we have a big conference next Thursday :
http://www.cases.public.lu/pratique/fc/congres/2005/03/24_cdm/index.html
ciao,
pst
--
Pascal Steichen
pascal.steichen(a)lilux.lu
Lilux ASBL
http://www.lilux.lu/