Linux's Security Capabilities

Denis Ducamp / Hervé Schauer Consultants - English translation: Frédéric Lavecot

Septembre 2000


Reproduction forbidden

1. Introduction

In this talk, two different aspects will be presented:

1.1 What is Linux ?

1.2 The main security functions of Linux 2.2

2. Capabilities

2.1 What is a capability ?

2.2 Linux's Capabilities

2.3 Processes Capabilities

2.4 Setting capabilities to processes

2.5 Setting capabilities to executable file

2.6 CREDITS

3. Linux Kernel Modules

3.1 What is a Kernel Module

3.2 Hazards

3.3 Advantages for the administrator

3.4 Advantages for crackers

3.5 Références

4. Accounting

4.1 Utilities

4.2 Requirements

4.3 Statistics

5. Filesystem ciphering

5.1 How does the filesystem ciphering work ?

5.2 Notes

5.3 Algorithms

5.4 Exemple

5.5 References

6. Misc.

6.1 Security patches

6.2 Distributions sécurisées

6.3 subterfugue

7. PAM (Pluggable Authentication Modules)

7.1 Configuration

7.2 Modules

7.3 References


HSC ® © Hervé Schauer Consultants 2000 - 4 bis, rue de la gare - 92300 Levallois-Perret
Phone : +33 141 409 700 - Fax : +33 141 409 709 - Email : <secretariat@hsc.fr>