/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! /* ALSO: Don't quote this header. It makes you look lame :-) */ Hey Everyone, Welp, I promised this was coming (actually, been promising for too long. A new version of both TrinityOS and the TrinityOS-archive has been released. I'll definately try to get these revisions out more offen then hold them up until I add MAJOR changes (the last PUBLISHED email update 4/24/00! ). I hope you like the new additions, fixes, etc. Like always, if you find any problems, spelling errors, requests for new features, etc, please let me know. http://www.ecst.csuchico.edu/~dranch/LINUX/index-linux.html#trinityos PS. 456 users and counting! Please let your friends, LUG buddies, etc know about TrinityOS. Without all your feedback, I can't make TrinityOS better! --David ChangeLOG --------------------- G 07/14/00 - Sent out the a notification to the people on the Updates list. * Sent Update * N - Moved all ChangeLOGS dated 04/09/00 and older to the arhives ----------------- N 07/09/00 - In the spirit of automating of building the TrinityOS docs, I have added the <TrinityOS rule set START> and <TrinityOS rule set STOP> tags to the strong IPCHAINS rule set so that I can have single place for the maintinance of the ruleset. Now I don't have to manually maintain and update the ruleset in both TrinityOS and in the TrinityOS-archive. Sorry for any previous differences between the two files. Thanks to Ken Kellam for the Perl code to do this. [Section 10] ---------------- N 07/06/00 - Merge over the ICMP and /proc changes to the rc.firewall archive ---------------- N 07/05/00 Fixed many spelling errors and downright english mistakes throughout the document: explict --> explicit implict --> implicit enviroment -->environment vunerable --> vulnerable ruleset --> rule set i.e. --> e.g. maintinance --> maintenance portscan --> port scan powerdown --> power down cablemodem --> cable modem impliment --> implement distro -->distribution etc --> etc. taylor --> tailor enduser --> end user thats --> that's immeadiately --> immediately occured --> occurred goto --> go to Removed the poor usage of too many ".." THANKS to "Roberts, Mike" <[EMAIL PROTECTED]> for all these. Better late the never eh Mike? I Wow! It looks like some URLs fell through the SGML conversion crack! I Missing URLs included: MLPPP, PPPoE, PPTP, and Netscape. N I also updated the version numbers for Sendmail (8.9.3 to 8.10.2) and Wu-FTPd (2.6.0 to 2.6.1). G Finally, I also added URLs for OpenSSH, APCs Powerchute for Linux, and ViperDB (Tripwire clone). [Section 5] N Updated the fact that I now currently use both Mandrake 6.1 and 7.0 [Section 6] G Added to the TCP Wrappers section how to support advanced logging and sending text banners to remote clients. A belated thanks to [EMAIL PROTECTED] for this one. [Section 8] I Updated the IPCHAINS rc.firewall to v3.70 to reflect all the previous significant but unpublished changes and also the following: G - Updated the rc.firewall to use newer methods to get the EXTIP and EXTBROAD addresses using two programs instead of four. Thanks to "John E. Christ III" <[EMAIL PROTECTED]> for this one. N - Fixed a spelling error of internface --> interface in the SMB section G - Added additional explicit ACCEPT traffic for INDENT traffic in the INPUT and OUTPUT sections N - Deleted the SECONDARYDNS varable from the firewall rule set as it did nothing nor could it since both TCP and UDP DNS traffic must be wide open to the world anyway. G - Added several new /proc terms to secure or ensure settings are set: - Added TCPSYN checking - Added Sanity ICMP filters for - ICMP broadcasts - ICMP bad error packet - ICMP redirects - Added Sanity filters for source-routing and spoofed packets G - Added explict but disabled by default filters for different types of ICMP traffic to both the INPUT and OUTPUT sections N - Added more subsection labels to section 10 to make the section easier to navigate G - Deleted the the SECONDARYDNS varanble in the firewall because it wasn't used and authoritative DNS servers must have both UDP and TCP DNS ports open to the world to work properly. N - Cleaned up the DHCP / PUMP issue description section a little G - Added a disabled OUTPUT section to support APC Powerchute for Linux G - Added the new top banner to the rc.firewall file and added a top section for enduser's personal notations and version changes N - Added a disabled option for the ICQ MASQ module I - For some reason, SMTP OUTPUT on the EXTERNAL interface was enabled by default. This is now DISABLED by default. N - Put #s in front for the SECUREHOST OUTPUT echo statements though the IPCHAINS statements were already disabled. Thanks to "Ian Chilton" <[EMAIL PROTECTED]> for the /proc and ICMP ideas. [Section 10] G Added inline comments to the trinityos.mc Sendmail config files for both the Sendmail 8.9 and 8.8 configs to explain what each line does. [Section 25] N Changed the name of the tape backup section to something a little more straitforward and obvious [Section 29] N Updated the PCMCIA section a little [Section 34] N Updated the APCUPSd section to note that though the official APC Powerchute for Linux software not only works but its FREE, but unfortunately it is NOT compatible with MS Windows Powerchute clients for over-the-network shutdowns. [Section 36] N Updated the IPSEC section to note that typical IPSEC VPNS are running a 168-bit cipher. [Section 47] ---------------- N 07/03/00 Updated all the old/dead links for IPCHAINS and Netfilter N Cleaned up all the stray "X" marks in the URL section. Thanks to John Hardy <[EMAIL PROTECTED]> for the prod. [Section 5] N Noted that I have taken over the POP-Auth documenation and it will be posted to my WWW site soon. [Section 5] N Noted in the various firewall rule sets that newer versions of Pump now support script execution upon lease bringup, renew, etc. Thanks to Mark Baysinger <[EMAIL PROTECTED]> for this one. [Section 10] N Updated the verbage in the Kernel Compiling section to reflect that the 2.4.x kernels are about upon us. N Updated the 2.2.x kernel example to reflect a 2.2.16 kernel [Section 12] G Added some headers to the two different NTP scripts and also added some inline comments for users who want to set the date/time via NTP but save the results in UTC format. Thanks to Anders Oreback <[EMAIL PROTECTED]> for this one [Section 26] G Added a new section called "Gracefully transitioning Internet domains through a IP address or ISP change". This section takes you step by step on how to best notify the Internic and DNS servers of the change without having your domain actually stop responding to email, etc. [Section 51] G Oh wow.. I didn't realize that Section 51 had the wrong name! Before, it had a title for patching Tar to support BZip2 and NOT "Thoughts and procedures about Patching your distribution". Thanks to Chuck Hartley <[EMAIL PROTECTED]> for catching this. Regardless, its now section 52 to make room for the "Changing ISPs and/or IP addresses" section [Section 52] ---------------- G 07/02/00 Fixed all the broken links that were pointing to http://www.ecst.csuchico.edu/~dranch/LINUX/TrinityOS-files They should have been pointing to TrinityOS-security. N Fixed all the "layed" spelling errors. Thanks to [EMAIL PROTECTED] for this one. N Removed the line from the TODO list: * Impliment external 10.x.x.x and 172.16-31.x.x packet filtering [Section 2] N Added to the TODO list to modularize the rc.firewall rule set so that users can update their firewall without having to re-edit and tailor it to their needs. [Section 2] N Fixed the formatting issues of the /etc/ftpconversions file edit. Thanks to [EMAIL PROTECTED] for the sharp eye. [Section 7] I Updated the rc.firewall rule set to v3.60 # Added port 445 for Windows2000 CIFS / SMB filtering for both INPUT and # OUTPUT. Also enhanced the informational section to explain what each # port does # Added EXTENSIVE INPUT and OUTPUT filters for the IANA reserved # TCP/IP addressing scheme This one comes from good discussions with [EMAIL PROTECTED] # - Added explicit though disabled Multicast filtering on the extnernal # interface per many users requests. [Section 10] I Fixed a typo where the second CHMOD should have been for /home/chroot-dns-int and not ext. I Updated the root-hints-update script to v2.1 # v2.1 - Fixed a typo in the CHMOD of the external root-hints.sb file # - Fixed the file ownership of the internal root-hints.db file # - Changed the default path of where the new root.hints.new file # is to be placed # - Updated to have a backup copy of the INTERNAL hints file and not # just have an EXTERNAL backup N Added a new subsection to get to the root-hints.db script easier # A strong Thanks to [EMAIL PROTECTED] for these corrections [Section 24] ---------------- *C* 06/25/00 Updated the 2.2.x kernel section to remind users that 2.2.16 is and is the ONLY secure kernel version available. See below. [Section 5] *C* Roughly June 7th, it was found that Linux running kernels less then 2.2.16 had a TCP exploit. I have updated the rc.firewall to reflect this info: NOTE: All 2.2.x Linux kernels prior to 2.2.16 have TCP exploit that **** that when combined with tools like Sendmail can leed to a ROOT compromise. In addition to this, all kernels less than 2.2.11 have a fragmentation bug that renders all strong IPCHAINS rule sets void. It is CRITICAL that users upgrade the Linux kernel to at lease a 2.2.16+ kernel for proper firewall and system security. [Section 10] ---------------- N 06/24/00 Added to the DNS section how to determine the version of BIND simply using "nslookup". [Section 24] ---------------- G 06/22/00 Updated the /etc/logrotate.d/syslog file to reflect that klogd in /sbin and NOT /usr/sbin in RH 6.1 Thanks to for catching that [EMAIL PROTECTED] [Section 8] ---------------- N 06/19/00 Added a few options to the TrinityOS "Futures" section - Named compiling walk-thru - GnuPG / PGP support [Section 3] G Heavily went over the DNS section - Cleaned up a lot of the text, fixed many formatting and and layout issues throughout this section, etc. - Fixed two typos where the path for 212.0.200.100.db and 192.168.0.db were pointing to chroot-ext and chroot-int instead of chroot-dns-ext and chroot-dns-int [Section 24] I It should be noted that as I mentioned above in the DNS changes, I plan on going through all the various TrinityOS section and cleaning out all the old formatting issues, etc that were left over from the SGML port. Though this will take some time, TrinityOS will ultimately read and look better. It should also be mentioned that I'm in the process of bringing up my new Linux box. Since this machine is MODERN, I'm updating TrinityOS to reflect the new changes in Linux such as the hardware map, Software RAID, as well as updated configurations for Sendmail, etc. ---------------- N 05/28/00 Updated the Getdate URL [Section 5] G Updated the IPCHAINS rule set to v3.59 # - Fixed an error for the Squid re-direction where all # detination traffic was going to BROADCAST instead of # INTLAN. Thanks to [EMAIL PROTECTED] for catching this. # # - Fixed an error where global SMTP allows on all # interfaces were actually limited to the EXTIP address. # This should have been UNIVERSE. # # - Fixed a typo where the AOL filtering example had the # SMTP port in destination and not the source address # field. # Thanks to [EMAIL PROTECTED] for these two reports. [Section 10] G Made some important updates to the DNS section: - The in.addr file for the external DNS zone had the wrong IP address in it. - Missed setting the chown ownerships for the external zone directories. Thanks to [EMAIL PROTECTED] for catching these. [Section 24] ---------------- N 04/25/00 Ok, I've started to clean up the SGML code by hand. Though Ian's Perl code did 95% of the work, it isn't as pretty as it should be. N I *DO* know that the PDF looks like crap. I have a possible solution w/ the aid of the new version of GhostScript but it will have to wait for a week or two. N Some of the ASCII border art was mis-aligned. I have started this cleanup but it will take some time to clean up all issues. N The CMOS setup table was mis-aligned. Fixed. [Section 4] N Started to cleanup the formatting of this section. You will notice that the fixed sections DON'T have the "X" in front of them (the old "checkmark" setup). I also updated the 2.2.x kernel to be 2.2.14 [Section 5] N Updated the URL of the TrinityOS security script [Section 7] N Fixed the formatting issues of the MASQ flowchart. [Section 10] G Fixed a typo where copying and then moving /usr/sbin/named-ext should have been named-xfer. Thanks to [EMAIL PROTECTED] for catching this. [Section 24] ---------------- .----------------------------------------------------------------------------. | David A. Ranch - Linux/Networking/PC hardware [EMAIL PROTECTED] | !---- ----! `----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----' _______________________________________________ Masq maillist - [EMAIL PROTECTED] Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES UNSUBSCRIBING! or email to [EMAIL PROTECTED] PLEASE read the HOWTO and search the archives before posting. You can start your search at http://www.indyramp.com/masq/ Please keep general linux/unix/pc/internet questions off the list.
