Re: Red Hat ES3.0 Security

From: Darko Gavrilovic (dgavrilovicAThushmailDOTcom)
Date: 03/30/05


Date: Wed, 30 Mar 2005 06:05:42 -0600

HansF <News.Hans@telus.net> wrote in
news:pan.2005.03.30.12.17.35.393535@telus.net:

> On Wed, 30 Mar 2005 10:26:32 +0000, Chris Mewton wrote:
>
>> Can someone advise if RH ES3.0 is secure enough out of the box to
>> perform ecommerce function without being behind a seperate firewall?
>> I guess yes, but have been told no.
>> regards
>>
>
> Since there have been patches written to ES3; since patches continue
> to be written; and since the statement implies that no one will be
> looking for and applying patches; IMO, the answer is NO.

Hi. Other than patching, I think the OP is asking, can he/she assume that
the default setup as released by Red Hat is secure without him/her having
to go through the different settings and start hardening the security
settings.

I don't use RedHat, but I assume that at the very least you will have to
go through and start looking at the different services running and start
disabling what you don't need.

-- 
"Why do they call it rush hour when nothing moves?", Robin Williams


Relevant Pages

  • Re: Open Ports....How to block them all....?
    ... > I keep it up to date with SP's and Patches but find that the server keeps ... Frequently this happens through an IIS ... Ways to secure your system are detailed at: ...
    (microsoft.public.inetserver.iis.security)
  • Re: PodXT Live
    ... create patches at the volume you'll be using them. ... using the Carvin because it's easier to get it to flat than some other ... I'm having to adjust settings again. ... am testing this at gig volume and so far so good. ...
    (alt.guitar)
  • Re: Encrypted file system without initial password:
    ... > This was not a question about potential root exploits. ... These settings can then be password-protected in the BIOS ... >> software-based security measure would be useless. ... the system should be fairly secure. ...
    (comp.os.linux.security)
  • Re: Help!!! with a Trial SSL Cert
    ... The page you are trying to access is secured with Secure Sockets Layer ... browser settings. ... If your Network Administrator has enabled it, ... can examine your network and automatically discover network connection ...
    (microsoft.public.inetserver.iis.security)
  • Re: Internet Kiosk Group Policy
    ... you can configure policy tight enough so they can't ... that with the proper combination of policy settings you can achieve a very ... tight and secure environment. ... hard drive in the BIOS and setting a BIOS password. ...
    (microsoft.public.windows.group_policy)