Hans,
        security is tough. guard the passwords, use only ssh and never
divulge root's password. backup all the important stuff onto a box that is
pretty much locked down: no telnet, no ftp, "no nothing". only ssh and
even that with password access disabled, very few users, say 2 and only
rsync over ssh. that means hands on - anything else will make passphrase
visible.
        as to what people really do in schools: subscribe to k12os.org
list. there are people there with really extensive experience in running
ltsp in school environment. julius

On Tue, 5 Mar 2002, Hans Ekbrand wrote:

> On Tue, Mar 05, 2002 at 03:18:33PM -0500, Julius Szelagiewicz wrote:
> > Morten,
> >     do yourself a huge favor and look up the K12Ltsp aka K12OS at
> > <http://www.k12os.org>
> >     they have just what you need; a full distribution based on rh7.2
> > and ltsp 3.0 meant for use in the schools! it is awesome! and it works
> > right out of the box.
> >     as to what you need for server(s), there are 2 schools of thought.
> > 1 says "many little servers, if one fails, it is not a disaster". school 2
> > says "any filure is a disaster to the administrator and one big
> > "DEPENDABLE" server is better and cheaper than many small ones. both
> > approches have merit. from my experience with systems big and small i
> > learned that one server per geographical location works best for high
> > bandwidth application, everything else is better done on a single big
> > server. more to a point, i've run single server for 3000+ users with >no<
> > that is 0 downtime in 1.5 years and i've run setups with 9 servers for 50
> > users with lots of downtime. server quality rules. as to the load: a
> > single 4 processor 1GHz or better with at least 4GB should be adequate
> > provided that not all 160 users hit various applications at the same time.
> > i would go for more memory first, more processors second and more speed
> > third. good luck, and really look up the k12os distribution. julius
>
> Since I might go and offer LTSP to some schools around here, I find
> your information most valuable Julius. I had a glance at k12linux web
> site, but I did find it lacking in the security area. I remember that
> security problem often plagued the administrators at your high school,
> and many of us students used most of the time hacking/cracking in
> those labs (not me though).
>
> Limiting users cpu load is one problem. Another one is if one user do
> disk-access-intensive things like:
>
> grep -r foo /
>
> How do people on this list handle security problems like these with
> ltsp in, say high-schools?
>
> Hans Ekbrand
>


_____________________________________________________________________
Ltsp-discuss mailing list.   To un-subscribe, or change prefs, goto:
      https://lists.sourceforge.net/lists/listinfo/ltsp-discuss
For additional LTSP help,   try #ltsp channel on irc.openprojects.net

Reply via email to