Don,

> I see this as a VERY SERIOUS issue that needs to be looked
> into.  RPM CAN NOT re-enable services that I've disabled!

Strongly agree !

> There are some services that should be enabled by
> default, in my opinion:
> 
> Workstation installs:
> xfs, cups/lpd, crond, drakfont, gpm, harddrake, kudzu,
> sound, network, usb, sshd (if installed), xinetd (but
> none of the services), numlock

This looks good.

> Development installs:
> Probably similar to the above..
> 
> Server installs:
> cups/lpd, crond, network, usb, sshd, xinetd (maybe some
> of the services), nfs, smb, httpd, ypserv (if
> installed), ldap, mysql, named, postfix, portmap, etc.

Disagree. Yes, these can be part of the installation, but
absolutely do NOT turn on the services which are for remote
access, like nfs, smb, httpd, ypserv, mysql, named, ...

People installing servers are more knowledgeable about
Unix/Linux, and they (like me) will turn them on when
ready.  First an administrator needs to put security
TCP wrappers in place, one service at a time.

Thanks... Dan.



Reply via email to