> I don't think I've ever seen Bastille Linux mentioned here before.

Well, Bastille is not a distribution, just a script that does a number
of common configuration changes to improve the security of a system. It
suffers from a combinatoric problem -- it's hard to keep up with all the
possible security stupidities one can possibly commit with people who
work on a volunteer basis. 

AFAIK, Bastille hasn't been very regularly maintained in a while. Lots
of people were really hot on it for a while, and it's kind of dropped
off since then. 

> I's a few years since I looked at it (RHL 7.x or so I think) and then
I
> thought it somewhat overrated. Useful perhaps for a sysadmin who
doesn't
> know properly what he's doing.
> I will acknowledge usefulness as an educational tool.

I like to compare it to brushing your teeth. You'll still get cavities,
but at least you've made an effort to stave off the most obvious/stupid
problems. 

> Also, I don't recall seeing it as part of a distro, though Debian
> probably has it, but it's not part of a standard install.

It never was, AFAIK. Debian still has a current package for etch, but
haven't tried it. 

> > lnx001:~ # bastille -b
> > NOTE:    Entering Critical Code Execution.
> >          Bastille has disabled keyboard interrupts.
> >
> >
> > Can't locate Bastille/IPFilter.pm in @INC (@INC contains: /usr/lib
> > /opt/sec_mgmt         /bastille/lib /usr/lib/perl5/site_perl/5.8.3
> > /s390x-linux-thread-multi /usr/lib/p         erl5/site_perl/5.8.3
> > /usr/lib/perl5/site_perl /usr/lib/Bastille /usr/lib/perl5/s
> > ite_perl/5.6.0/i386-linux
/usr/lib/perl5/5.8.3/s390x-linux-thread-multi
> > /usr/lib         /perl5/5.8.3 /usr/lib/perl5/vendor_perl/5.8.3
> > /s390x-linux-thread-multi /usr/lib/         perl5/vendor_perl/5.8.3
> > /usr/lib/perl5/vendor_perl .) at /usr/sbin/BastilleBackE         nd
line
> > 309.
> > BEGIN failed--compilation aborted at /usr/sbin/BastilleBackEnd line
309.

It looks like a Bastille Perl module either didn't get installed, or
conflicts with an already installed module. This is probably a packaging
error rather than a code problem. 

----------------------------------------------------------------------
For LINUX-390 subscribe / signoff / archive access instructions,
send email to [EMAIL PROTECTED] with the message: INFO LINUX-390 or visit
http://www.marist.edu/htbin/wlvindex?LINUX-390

Reply via email to