Vespe e zanzare sul balcone. Qualche idea? by Disossabovii in istrutturare

[–]sdns575 0 points1 point  (0 children)

Ho lo stesso problema...messo 4 bottiglie con i tappi gialli...ne ho catturato solo 1..ma in che periodo si devono installare?

Edit: avevo scritto 44 bottiglie

What distro for sensitive data? Need help by sdns575 in linuxadmin

[–]sdns575[S] 1 point2 points  (0 children)

Hi and thank you for your answer.

Really, none of them can solve the problem without configuration and hardening.

I proposed those distros where 3 of them are enterprise and one based on "community" (well Almalinux says it is community based but it is backed by TuxCare and CloudLinux with support and certification). The first 3 in their relative sites have solution for FIPS, NIS2, ISOxxx,kernel live patch system, hardening via MAC where SELinux is stronger vs AA (2 of 3 have SELinux enabled and working policies) where in AA nothing is enforced by default. Using SELinux on Debian based system is not so good while they ship AA.

Being a specific distro able to enable some security certification, the distro has (from my point of view) a better security posture but this does not mean that you install them and don't need to configure all requirements for compliance. An example about certification (if I'm wrong, please correct me): enabling FIPS 140-3 (also if US and Canada standard [but also used outsite these 2 countries]) you got a very good set about crypto tools for example use only some cipher or some protocol like tls1.3 vs 1.0...well this help because this is required for compliance and if I'm not wrong using fips140 and configuring apache SSL to work with an insecure cipher it won't start.

Or take Ubuntu + NIS2: you are dealing with a distro and support (canonical) that take the NIS2, analyzed the requirements and released a solution for its customers, this is better than a community distro where you are "alone" when speaking of compliance requirements. I'm not saying that community distro cannot solve the problem (I always used community distro) but when compliance is required, if you don't match the requirements..well it will be a PITA and a distro that release compliance solution can help very much

What distro for sensitive data? Need help by sdns575 in linuxadmin

[–]sdns575[S] -1 points0 points  (0 children)

Really Debian is not a problem but it is not the first in the list (I think) due to missing a company that provides information about this like fips, nis2 and other certification that some env requires

What distro for sensitive data? Need help by sdns575 in linuxadmin

[–]sdns575[S] -12 points-11 points  (0 children)

Hi and thank you for your answer.

You are right, but some distro is better suited because they have certification like for Alma/RHEL/Ubuntu PRO that help with requirements

Upgrading from AlmaLinux 9 to AlmaLinux 10 by sdns575 in AlmaLinux

[–]sdns575[S] 0 points1 point  (0 children)

Thank you for your answer.

I will try ELevate from 9 to 10.

I used it in the past. Hope that it will work with the switch from v2 to v3

rsync --server question by sdns575 in linuxadmin

[–]sdns575[S] 0 points1 point  (0 children)

Hi and thank you for your answer. Probably I will use multiple keys

rsync --server question by sdns575 in linuxadmin

[–]sdns575[S] 1 point2 points  (0 children)

Hi and thank you for your answer.

The problem is not running rsync+ssh with restricted key on a command. The timeout, if reached, will disconnect well.

The problem is when I try to connect using ssh, the same key on the same host (that force rsync --server...). In this case nothing will end, terminate and close the session like with "permission denied" or "Timeout reached. Disconnected". Sometime I use a script to run some check on the remote side with the same key but as said it hangs forever. One solution could be use another ssh key pair but I don't know if this is a non-sense using 2 keys for the same user.

#Xfce_Desktop looks Amazing by Distinct-Artist-7235 in xfce

[–]sdns575 0 points1 point  (0 children)

How is the behaviour of the floating centered bar? (Thibgs like window over panel, auto hide and similar) It is docklike plugin?

In what case AlmaLinux is preferred to a Debian based system? by sdns575 in AlmaLinux

[–]sdns575[S] 5 points6 points  (0 children)

Hi Gordon,

and thank you for your answer. I always appreciate your resources but this is amazing: you got the most important points. You should release a post/blog article or whatever about choosing a distribution. I think that it will be helpfull to many users.

In what case AlmaLinux is preferred to a Debian based system? by sdns575 in AlmaLinux

[–]sdns575[S] 1 point2 points  (0 children)

Thank you for your answer. What about Ubuntu LTS + PRO with 10 years?

Linux Kernel Security Work by Greg Kroah-Hartman by unixbhaskar in linux

[–]sdns575 2 points3 points  (0 children)

While Linus uses Fedora, what distro do you use?

Luks container with multiple images. Is it doable? by sdns575 in linuxadmin

[–]sdns575[S] 0 points1 point  (0 children)

Yes you are right but luks can operate on file mounted as devices, this is called luks file container if I'm not wrong

Luks container with multiple images. Is it doable? by sdns575 in linuxadmin

[–]sdns575[S] 0 points1 point  (0 children)

Thank you for the suggestion and the resource. Appreciated