RE: AW: Re: Selecting OS for High-availability/mission-critical w eb portal



-----Original Message-----
From: "J. Simonetti" <jeroen@xxxxxxxxxxxx>@DSI
Tbh, I totally disagree here. LFS is nice to get started when learning
linux,

That's why I said, it may help you.

but for a critical servers you need some sort of package
management and well maintained repository.

And then? apt-get update; apt-get upgrade; with cron every hour?
You are kidding.

You cannot spend your time
updating and compiling software and fixing patches every time there is
an update whilst the next zlib/ssl exploits are floating
around the net.

I have to spend the time, and if my server is REALLY critical, I will have
to. Ans most of the time, my team is faster than debian.

One thing I do agree with is creating a custom kernel suited for your
hardware.

Suited for the hardware and implementing a couple of security features.

I think the basis for a mission critical server is its hardware. Make
sure you select hardware wich is well known and widely
supported for the
distro you intend to run. Don't choose exotic hardware raid cards just
because they might work good. Choose the one wich has the
best drivers.
The same goes for all other hardware offcourse.

The hardware can do a lot for availability, of course, but nothing for
security (except physical security)

Now for the distro to choose there is a wide variety which
can be used.
Whatever your needs are, pick a distro with good support. Depending on
what kind of server you need to run choices could be (but are not
limited to) Openbsd for firewalls/security, Solaris for stability and
support,

Ever tried to customize your Solaris-kernel?

Debian for feature richness or Redhat Enterprise for a large
hardware base and its support.
If pure stability is the only factor in my decision I would go for
Openbsd or Solaris and choose hardware which is 'known-to-be-good' for
those platforms.


Best regards

--
Christoph Gruber, CISM
Chief Security Officer
WAT1SD, Security & Data Protection
WAVE Solutions Information Technology GmbH
A-1090 Wien, Nordbergstraße 13
Tel.: +43 (1) 71730-53514, Fax: +43 (1) 71730-54230
mobile: +436648122661
christoph.gruber@xxxxxxxxxxxxxxxxxx
http://www.wave-solutions.com





Relevant Pages

  • Re: solaris 1/6 on Sunfire v245 ?
    ... impossible to add that kernel and module support in later on so the minimum ... pragmatic and these servers had to be ready "yesterday". ... the same Solaris 10 OS image on all servers in order to ease maintenance. ... hardware that it doesn't support, you and your whole team just went into ...
    (comp.unix.solaris)
  • Re: Security and EOL issues
    ... OS software resources are designed that reserved ram and disk space among other resources, to reflect what current hardware size is available. ... (There was a security patch a few years ago that could not be applied to NT4 as it required more resources then NT4 could provide. ... Installing air bags requires that the automobile manufacturer design, test, ... Computer Emergency Response Teams, and Digital Investigations. ...
    (Security-Basics)
  • Re: Blade 1500 - a "sound" purchase?
    ... Does solaris come with audio stuff to support the hardware? ... but not much else in the way of audio. ... I don't know of any with drivers on Solaris. ... Hardware I/O driver list. ...
    (comp.unix.solaris)
  • Re: High-precision timers on x86 uniprocessor
    ... > I don't think we support such timers on Intel hardware ... The reason why I thought Solaris 10 does support this is one blog entry ... operating systems have relied a regular clock interrupt. ...
    (comp.unix.solaris)
  • Re: Wikileaks, secondary effects
    ... Those last people are not in the business of security, ... local to network storage for documents and applications. ... Most workstations have no real need to attach peripherals aside from mouse and keyboard and since the lifetime of a desktop is about three years, "damaging" hardware to make it more secure is not a big deal. ... The professor who owned the project was under the fond illusion that if he just got all the static timing right, then all the bugs were *gone* This guy and many others in the 1980s and early '90s didn't grasp the complexity of a CPU or an OS and that the only way to wring bugs out is by users finding them. ...
    (sci.military.naval)