Sounds like a different philosophy to me. Openbsd provides minimal
functionality by default, but allows users to add there own via
the PORTS collection. Redhat includes a wide range of network services
by default, requiring tweaking a GUI tool to get them to start on
bootup.
Redhat has security auditors, and contributes patches to numerous tools.
So if you need a DNS server, you installed openbsd, then installed
ISC's named from ports you have the same DNS security problems of the
rest of the world:
ftp://ftp.openbsd.org/pub/OpenBSD/patches/2.7/common/038_named.patch
Similar with ftpd I.e.:
http://www.openbsd.com/advisories/ftpd_replydirname.txt
So as long as your smart enough to enable only what you need the
security isn't any different.
For the most part openbsd seems to follow the same
OhMyGodThereIsAnotherRootExploit and issues patches accordingly.
Not that openbsd isn't a fine unix distribution, I just fail to
see this "huge" security difference just because the exploitable
programs are in PORTS instead of installed by default.
Personally I like redhat simply because it has good functionality
out of the box, offers significantly more verification/coverage testing
then other distributions I've used (mandrake, slackware, even the old SLS),
and they get the security patches out usually within 24 hours minimizing
my security exposure.
Often redhat has to "reissue" patches because they receive wide
publicity months after redhat patches them. For instance the April 1st
adore virus uses an exploit that was patched in October 2000.
--
Bill