/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Hey Everyone,

LOTS of big changes in this one.  If you could give the
CHROOTed and Split DNS zone setup some testing, I would
appreicate it!

Also.. the sendlogs script is fixed too.  See the log
below what happened.


Anyway, 413 users on the list now!

--David



N       04/09/00        Changed the name of the DNS section to 
        * Sent  reflect that the TrinityOSdocumentation 
          Update        now tells users how to setup DNS in both 
          Update*       a CHROOTed and SPLIT Zone environment.
                        [Section 2]

N                       Removed the "Edit and move /var/log/sendlogs 
                        to /usr/local/sbin" line from the Future 
                        Features section.  It was already done.
                        [Section 2]

N                       Removed the "Update the DNS setup to be 
                        a SPLIT-DNS setup for additional internal 
                        security" Future Feature line now that its 
                        completed.
                        [Section 2]

N                       Updated the Feature section to reflect that 
                        DNS is now done in a both a CHROOTed and 
                        SPLIT Zone fashion.
                        [Section 3]

I                       In addition to finding that the copy of 
                        Sendlogs in TrinityOS was old compared to 
                        the archive, I reversed a change I made a 
                        while back.  Basically, now dates from 
                        01-09 will now work properly.
                        [Section 9]

N                       Moved all IPCHAINS firewall changelogs 
                        older than v3.50 to the old-updates log.  
                        The URL is both just above this and at the
                        end of TrinityOS.
                        [Section 10]

G                       Updated the IPCHAINS rc.firewall to v3.57

                        #     - Added some spaces in front of the 
                        #       work "Optional" for prettier output 
                        #         upon loading.
                        #     - I've rearranged the the enabling of 
                        #         FORWARDING -before- the enabling of 
                        #         MASQUERADING since IPCHAINS complains.  
                        #     - As of 2.2.12, the IP_ALWAYS_DEFRAG 
                        #       option has been omitted and is now a 
                        #       /proc configured option.  I have now 
                        #       added this to the FORWARD section.
                        #     - Added an echo statment and additional 
                        #         SILENT blocking statements for SMB 
                        #       traffic on the external interface

                        [Section 10]

N                       More for a self reminder, I added how to 
                        address a NIC in Redhat speak at the end of 
                        this section.
                        [Section 16]
 
I                       Wow!  This was a LOT more work than I expected 
                        but I've finally updated the DNS section to 
                        now configure BIND to be in both a CHROOT'ed 
                        jail (for security) and have SPLIT Zones for 
                        internal and external internfaces.  
                        Please see the section for more details on what 
                        all this means.  I have also slightly 
                        reorganized this section and updated and moved 
                        the root-hints script.
                        [Section 24]

I                       I have updated the TrinityOS archive with all 
                        this as well.

------------------

N       04/08/00        Added a URL for additional SSH tunneling help.  
                        Actually, I just moved it from Section 30 to 5.  
                        I did the same for the Security HOWTO from 
                        section 8 to 5.
                        [Section 5]

G                       Updated the permissions for the various 
                        /etc/cron.* files and also updated them in 
                        the TrinityOS-security script.
                        [Section 7]

N                       Moved the changing of permissions of 
                        /bin/rpm from the bottom of section 8 to 
                        section 9.
                        [Section 7 to 8]

N                       Moved and updated the URL for the Security 
                        HOWTO to Section 5.
                        [Section 8]

N                       Updated some of the verbage in the password 
                        section section.  Also cleaned up and expanded 
                        on the daemon enabling/disabling section for 
                        both BSD and SysV systems.
                        [Section 8]

G                       Added a note for the /etc/hosts.allow file 
                        to only use TCP/IP addresses and NOT DNS 
                        names since they can be spoofed.  I also
                        added an example in /etc/hosts.allow to 
                        allow all hosts on a given subnet.
                        [Section 8]

N                       Fixed two typos in the source directory 
                        when moving the logrotate config files for 
                        mysql and and squid.
                        [Section 9]

N                       Added changing the permissions of 
                        /etc/issue and /etc/issue.net.
                        I've also added this to the script.
                        [Section 9]

N                       Aligned TrinityOS with the script.  The 
                        "logit" script should be in /root.  I 
                        also fixed the perms on it.
                        [Section 9]

N                       Added the creation of the apropos 
                        database to the TrinityOS script.

N                       Noted that the "makewhatis" command 
                        now runs cleanly in Mandrake 7.0.
                        [Section 9]

I                       Holy Cow!  The /usr/local/sbin/sendlogs 
                        file in TrinityOS was VERY old.  Dunno 
                        how this escaped me!  Sorry!  The old 
                        version was 11/26/99, the new version is 
                        2/21/00!  The version in the TrinityOS 
                        archive was ok.
                        [Section 9]

N                       Updated the IPCHAINS firewall rulset to 
                        v3.56

                        # v3.56 - 04/08/00
                        #       - Added the /sbin path to the 
                        #       commented IPCHAINS lines for 
                        #       setting the TOS bits.
                        [Section 10]

N                       Deleted the changing the permissions of 
                        IPFWADM or IPCHAINS since they are 
                        duplicated in Section 8.
                        [Section 10]

N                       Noted that the 2.2.x kernels have PORTFW 
                        functionality built in.
                        [Section 11]

N                       Updated the top comments that TrinityOS 
                        covers the compiling of both 2.2.x and 
                        2.0.x kernels.
                        [Section 12]

N                       Updated and reformtted the section for 
                        editing of /sbin/ifup to reflect the line 
                        numbers for Mandrake 7.
                        [Section 16]

N                       Added the SSH section to reflect that 
                        SecureCRT v3.x support the SSHv2 protocol.  
                        I also noted that SSHv2 is not free for
                        commercial and educational use.  Thus, 
                        many people still use SSHv1 servers.  I 
                        also moved the URL for additional 
                        tunneling help from Section 30 to Section 5
                        [Section 30]

G                       Added a SysV script file to load SSHd for 
                        Linux systems like Redhat, etc.  I also 
                        clarified the existing system was for BSD 
                        systems like Slackware, etc.  I also added 
                        a few more configuration options for 
                        disabling Xwindows and SSH tunnels.
                        [Section 30]

G                       Added a SysV script file to load SSHd to 
                        the TrinityOS-security archive.

------------------

N       04/04/00        ftp.cdrom.com has moved their Linux archives 
                        to ftp://ftp.freesoftware.com.  I have 
                        updated the URLs.
                        [Section 5]

------------------

G       04/02/00        Updated the distro section to reflect Redhat 
                        6.2 and my thoughts and worries about Mandrake 
                        7.0's installer.
                        [Section 6]

I                       Added a security alert / patch recommendation 
                        for ircii
                        [Section 60]

------------------

N       04/01/00        Updated the name of the email section to to 
                        reflect the support of IMAP4 as well.
                        [Section 2]

G                       Added a URL to a HOWTO on the LDP for 
                        supporting multple virtual domains for email.
                        [Section 5]

G                       Added a large description of what UUCP, POP3, 
                        and IMAP4 are, how they work, and how they are 
                        better/worse.  I also re-wrote part of it to 
                        reflect both POP3 and IMAP4 and IPFWADM and 
                        IPCHAINS.
                        [Section 28]

N                       Added a pointer to Section 5 for users that 
                        need to setup virtual domains for email.
                        [Section 28]

I                       Fixed a type where I was restarting syslog and 
                        NOT crond as I was describing.  Thanks to 
                        [EMAIL PROTECTED] for catching this silly 
                        mistake.
                        [Section 41]

I                       Fixed a typo in the TrinityOS archive where 
                        "touch /etc/dhcpd.leases" had a stray "A" at 
                        the end of the line.
                        Thanks to [EMAIL PROTECTED] for that one.

------------------

.----------------------------------------------------------------------------.
|  David A. Ranch - Linux/Networking/PC hardware         [EMAIL PROTECTED]  |
!----                                                                    ----!
`----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----'


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to