Operating System - Linux
1830246 Members
1934 Online
110000 Solutions
New Discussion

chroot bind, squid, sendmail and httpd

 
SOLVED
Go to solution
Maaz
Valued Contributor

chroot bind, squid, sendmail and httpd

Hello Dear Gurus

OS: rhl9 and FC2

bind, sendmail, apache and squid are running. I have to improve security by implementing chrooted environment for the above mentioned servers(bind, sendmail, squid and apache).

So i want to know that is there any rpm which by default installed the above mentioned servers in chrooted mode/environment ? or should i have to do some configuration to configure/run the servers in chrooted environment ?

Any help will be highly appreciated ;)

Thanks in adv.

Regards
Maaz
3 REPLIES 3
Kodjo Agbenu
Honored Contributor
Solution

Re: chroot bind, squid, sendmail and httpd

Hi,

Have you tried Bastille Linux ?

www.bastille-linux.org

It is a set of perl scripts that helps enhancing OS security. Few years ago I used it sucessfully to chroot BIND services, and I guess it can be helpful on other TCP/IP services.

Good luck.
Kodjo
Learn and explain...
Steven E. Protter
Exalted Contributor

Re: chroot bind, squid, sendmail and httpd

Fedora Core 3 runs BIND out of the box in a chroot jail. You might want to consider and upgrade if your hardware is supported.

sendmail security can be improved with procedures available at http://www.sendmail.org, but it can not specifically be run in a chroot jail, as far as I know.

ftp and apache can be partially configured for jail by Bastille Linux. In both cases there will be manual steps for you to perform, left in a todo file.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Maaz
Valued Contributor

Re: chroot bind, squid, sendmail and httpd

Dear Kodjo Agbenu and SEP, I m highly thankful to u for the support/help.

I have assigned points... because I know that u people provide always the BEST/PERFECT help.

Yet I havent check the Bastille Linux... because I m bussy doing some other important tasks. But I m going to check it so soon, might be in a 1 or 2 days.

Still... Any Suggestions/help/assistance will be highly appreciated.

Regards
Mazz