|
|||||||||||
|
Re: Why not have firewall rules by default?
From: Javier Fernández-Sanguino Peña <jfs(at)computer.org>
Date: Sun Jan 27 2008 - 16:20:48 EST
Debian has a policy to install as few network services as possible in a default install and bind them to the loopback interface if possible. Please check out section 3.6 of the "Securing Debian Manual". IIRC:
Regards Javier PS: FWIW similar design decisions were taken on Ubuntu. They started with a 'no open ports policy' but switched recently to a strict, but more open policy, see https://wiki.ubuntu.com/DefaultNetworkServices Notice, however that the list of network services in Ubuntu was further reduced in the default install as it was (originally) more oriented toward Desktop systems (and not fully UNIX systems) Now they are even thinking on including a firewall in their default install (see https://wiki.ubuntu.com/UbuntuFirewall). Who knows, maybe Debian will reuse that in our default Desktop install. -- To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.orgReceived on Sun Jan 27 16:21:28 2008 This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:55:30 EDT |
||||||||||
|
|||||||||||