/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */ Hey Everyone, LOTS of big changes in this one. If you could give the CHROOTed and Split DNS zone setup some testing, I would appreicate it! Also.. the sendlogs script is fixed too. See the log below what happened. Anyway, 413 users on the list now! --David N 04/09/00 Changed the name of the DNS section to * Sent reflect that the TrinityOSdocumentation Update now tells users how to setup DNS in both Update* a CHROOTed and SPLIT Zone environment. [Section 2] N Removed the "Edit and move /var/log/sendlogs to /usr/local/sbin" line from the Future Features section. It was already done. [Section 2] N Removed the "Update the DNS setup to be a SPLIT-DNS setup for additional internal security" Future Feature line now that its completed. [Section 2] N Updated the Feature section to reflect that DNS is now done in a both a CHROOTed and SPLIT Zone fashion. [Section 3] I In addition to finding that the copy of Sendlogs in TrinityOS was old compared to the archive, I reversed a change I made a while back. Basically, now dates from 01-09 will now work properly. [Section 9] N Moved all IPCHAINS firewall changelogs older than v3.50 to the old-updates log. The URL is both just above this and at the end of TrinityOS. [Section 10] G Updated the IPCHAINS rc.firewall to v3.57 # - Added some spaces in front of the # work "Optional" for prettier output # upon loading. # - I've rearranged the the enabling of # FORWARDING -before- the enabling of # MASQUERADING since IPCHAINS complains. # - As of 2.2.12, the IP_ALWAYS_DEFRAG # option has been omitted and is now a # /proc configured option. I have now # added this to the FORWARD section. # - Added an echo statment and additional # SILENT blocking statements for SMB # traffic on the external interface [Section 10] N More for a self reminder, I added how to address a NIC in Redhat speak at the end of this section. [Section 16] I Wow! This was a LOT more work than I expected but I've finally updated the DNS section to now configure BIND to be in both a CHROOT'ed jail (for security) and have SPLIT Zones for internal and external internfaces. Please see the section for more details on what all this means. I have also slightly reorganized this section and updated and moved the root-hints script. [Section 24] I I have updated the TrinityOS archive with all this as well. ------------------ N 04/08/00 Added a URL for additional SSH tunneling help. Actually, I just moved it from Section 30 to 5. I did the same for the Security HOWTO from section 8 to 5. [Section 5] G Updated the permissions for the various /etc/cron.* files and also updated them in the TrinityOS-security script. [Section 7] N Moved the changing of permissions of /bin/rpm from the bottom of section 8 to section 9. [Section 7 to 8] N Moved and updated the URL for the Security HOWTO to Section 5. [Section 8] N Updated some of the verbage in the password section section. Also cleaned up and expanded on the daemon enabling/disabling section for both BSD and SysV systems. [Section 8] G Added a note for the /etc/hosts.allow file to only use TCP/IP addresses and NOT DNS names since they can be spoofed. I also added an example in /etc/hosts.allow to allow all hosts on a given subnet. [Section 8] N Fixed two typos in the source directory when moving the logrotate config files for mysql and and squid. [Section 9] N Added changing the permissions of /etc/issue and /etc/issue.net. I've also added this to the script. [Section 9] N Aligned TrinityOS with the script. The "logit" script should be in /root. I also fixed the perms on it. [Section 9] N Added the creation of the apropos database to the TrinityOS script. N Noted that the "makewhatis" command now runs cleanly in Mandrake 7.0. [Section 9] I Holy Cow! The /usr/local/sbin/sendlogs file in TrinityOS was VERY old. Dunno how this escaped me! Sorry! The old version was 11/26/99, the new version is 2/21/00! The version in the TrinityOS archive was ok. [Section 9] N Updated the IPCHAINS firewall rulset to v3.56 # v3.56 - 04/08/00 # - Added the /sbin path to the # commented IPCHAINS lines for # setting the TOS bits. [Section 10] N Deleted the changing the permissions of IPFWADM or IPCHAINS since they are duplicated in Section 8. [Section 10] N Noted that the 2.2.x kernels have PORTFW functionality built in. [Section 11] N Updated the top comments that TrinityOS covers the compiling of both 2.2.x and 2.0.x kernels. [Section 12] N Updated and reformtted the section for editing of /sbin/ifup to reflect the line numbers for Mandrake 7. [Section 16] N Added the SSH section to reflect that SecureCRT v3.x support the SSHv2 protocol. I also noted that SSHv2 is not free for commercial and educational use. Thus, many people still use SSHv1 servers. I also moved the URL for additional tunneling help from Section 30 to Section 5 [Section 30] G Added a SysV script file to load SSHd for Linux systems like Redhat, etc. I also clarified the existing system was for BSD systems like Slackware, etc. I also added a few more configuration options for disabling Xwindows and SSH tunnels. [Section 30] G Added a SysV script file to load SSHd to the TrinityOS-security archive. ------------------ N 04/04/00 ftp.cdrom.com has moved their Linux archives to ftp://ftp.freesoftware.com. I have updated the URLs. [Section 5] ------------------ G 04/02/00 Updated the distro section to reflect Redhat 6.2 and my thoughts and worries about Mandrake 7.0's installer. [Section 6] I Added a security alert / patch recommendation for ircii [Section 60] ------------------ N 04/01/00 Updated the name of the email section to to reflect the support of IMAP4 as well. [Section 2] G Added a URL to a HOWTO on the LDP for supporting multple virtual domains for email. [Section 5] G Added a large description of what UUCP, POP3, and IMAP4 are, how they work, and how they are better/worse. I also re-wrote part of it to reflect both POP3 and IMAP4 and IPFWADM and IPCHAINS. [Section 28] N Added a pointer to Section 5 for users that need to setup virtual domains for email. [Section 28] I Fixed a type where I was restarting syslog and NOT crond as I was describing. Thanks to [EMAIL PROTECTED] for catching this silly mistake. [Section 41] I Fixed a typo in the TrinityOS archive where "touch /etc/dhcpd.leases" had a stray "A" at the end of the line. Thanks to [EMAIL PROTECTED] for that one. ------------------ .----------------------------------------------------------------------------. | David A. Ranch - Linux/Networking/PC hardware [EMAIL PROTECTED] | !---- ----! `----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----' _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
