/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! 
/* ALSO: Don't quote this header. It makes you look lame :-) */


Hey Everyone,

Welp, I promised this was coming (actually, been promising for too
long.  A new version of both TrinityOS and the TrinityOS-archive
has been released.  I'll definately try to get these revisions out
more offen then hold them up until I add MAJOR changes (the last 
PUBLISHED email update 4/24/00! ).  

I hope you like the new additions, fixes, etc.  Like always, if you 
find any problems, spelling errors, requests for new features, etc, 
please let me know.

http://www.ecst.csuchico.edu/~dranch/LINUX/index-linux.html#trinityos


PS. 456 users and counting!  Please let your friends, LUG buddies, etc
    know about TrinityOS.  Without all your feedback, I can't make
    TrinityOS better!


--David

ChangeLOG
---------------------

G   07/14/00   - Sent out the a notification to the people on the Updates list.
    * Sent
      Update *
N              - Moved all ChangeLOGS dated 04/09/00 and older to the arhives

-----------------

N       07/09/00   - In the spirit of automating of building the TrinityOS
docs, I
                 have added the <TrinityOS rule set START> and 
                 <TrinityOS rule set STOP> tags to the strong IPCHAINS rule set

                 so that I can have single place for the maintinance of the
ruleset. 
                 Now I don't have to manually maintain and update the ruleset
in
                 both TrinityOS and in the TrinityOS-archive.  Sorry for any 
                 previous differences between the two files.

                 Thanks to Ken Kellam for the Perl code to do this.
                 [Section 10]

----------------

N   07/06/00   - Merge over the ICMP and /proc changes to the rc.firewall
                 archive

----------------

N   07/05/00    Fixed many spelling errors and downright english mistakes
                throughout the document:

                explict --> explicit          implict --> implicit
                enviroment -->environment     vunerable --> vulnerable
                ruleset --> rule set          i.e. --> e.g.
                maintinance --> maintenance   portscan --> port scan
                powerdown --> power down      cablemodem --> cable modem
                impliment --> implement       distro -->distribution
                etc --> etc.                  taylor --> tailor
                enduser --> end user          thats --> that's
                immeadiately --> immediately  occured --> occurred
                goto --> go to

                Removed the poor usage of too many ".."

                THANKS to "Roberts, Mike" <[EMAIL PROTECTED]> for
                all these.  Better late the never eh Mike?


I               Wow!  It looks like some URLs fell through the SGML conversion
                crack!  

I               Missing URLs included: MLPPP, PPPoE, PPTP, and Netscape.  

N               I also updated the version numbers for Sendmail (8.9.3 to
8.10.2) 
                and Wu-FTPd (2.6.0 to 2.6.1).  

G               Finally, I also added URLs for OpenSSH, APCs Powerchute for
Linux,
                and ViperDB (Tripwire clone).
                [Section 5]

N               Updated the fact that I now currently use both Mandrake 6.1 and
7.0
                [Section 6]

G               Added to the TCP Wrappers section how to support advanced
                logging and sending text banners to remote clients.
                A belated thanks to [EMAIL PROTECTED] for this one.
                [Section 8]

I               Updated the IPCHAINS rc.firewall to v3.70 to reflect all the
previous
                significant but unpublished changes and also the following:

G               - Updated the rc.firewall to use newer methods to get the EXTIP
                  and EXTBROAD addresses using two programs instead of four.
                  Thanks to "John E. Christ III" <[EMAIL PROTECTED]> for
                  this one.

N               - Fixed a spelling error of internface --> interface in the SMB
section

G               - Added additional explicit ACCEPT traffic for INDENT traffic
in
                  the INPUT and OUTPUT sections

N               - Deleted the SECONDARYDNS varable from the firewall rule set
as it did
                  nothing nor could it since both TCP and UDP DNS traffic must
be wide
                  open to the world anyway.
       
G               - Added several new /proc terms to secure or ensure settings
are set:
                   - Added TCPSYN checking
                   - Added Sanity ICMP filters for
                   - ICMP broadcasts
                   - ICMP bad error packet
                   - ICMP redirects
                   - Added Sanity filters for source-routing and spoofed
packets

G               - Added explict but disabled by default filters for different
types of
                  ICMP traffic to both the INPUT and OUTPUT sections

N               - Added more subsection labels to section 10 to make the
section easier 
                  to navigate

G               - Deleted the the SECONDARYDNS varanble in the firewall because
it 
                  wasn't used and authoritative DNS servers must have both UDP
and 
                  TCP DNS ports open to the world to work properly.  

N               - Cleaned up the DHCP / PUMP issue description section a little
 
G               - Added a disabled OUTPUT section to support APC Powerchute for
Linux

G               - Added the new top banner to the rc.firewall file and added a
top 
                  section for enduser's personal notations and version changes

N               - Added a disabled option for the ICQ MASQ module

I               - For some reason, SMTP OUTPUT on the EXTERNAL interface was
enabled
                  by default.  This is now DISABLED by default.

N               - Put #s in front for the SECUREHOST OUTPUT echo statements
though the
                  IPCHAINS statements were already disabled.

                Thanks to "Ian Chilton" <[EMAIL PROTECTED]> for the /proc and
ICMP ideas.
                [Section 10]

G               Added inline comments to the trinityos.mc Sendmail config files
                for both the Sendmail 8.9 and 8.8 configs to explain what each
line does.
                [Section 25]

N               Changed the name of the tape backup section to something a
little more
                straitforward and obvious
                [Section 29]

N               Updated the PCMCIA section a little
                [Section 34]

N               Updated the APCUPSd section to note that though the official
APC Powerchute 
                for Linux software not only works but its FREE, but
unfortunately it is NOT 
                compatible with MS Windows Powerchute clients for
over-the-network                  shutdowns.
                [Section 36]

N               Updated the IPSEC section to note that typical IPSEC VPNS are
running a
                168-bit cipher.
                [Section 47]

----------------

N   07/03/00    Updated all the old/dead links for IPCHAINS and Netfilter

N               Cleaned up all the stray "X" marks in the URL section.
                Thanks to John Hardy <[EMAIL PROTECTED]> for the prod.
                [Section 5]

N               Noted that I have taken over the POP-Auth documenation and
                it will be posted to my WWW site soon.
                [Section 5]

N               Noted in the various firewall rule sets that newer versions of 
                Pump now support script execution upon lease bringup, renew,
etc.
                Thanks to Mark Baysinger <[EMAIL PROTECTED]> for this one.
                [Section 10]

N               Updated the verbage in the Kernel Compiling section to reflect
                that the 2.4.x kernels are about upon us.

N               Updated the 2.2.x kernel example to reflect a 2.2.16 kernel
                [Section 12]

G               Added some headers to the two different NTP scripts and also
                added some inline comments for users who want to set the
                date/time via NTP but save the results in UTC format.
                Thanks to Anders Oreback <[EMAIL PROTECTED]> for this one
                [Section 26]

G               Added a new section called "Gracefully transitioning Internet
                domains through a IP address or ISP change".  This section 
                takes you step by step on how to best notify the Internic and
                DNS servers of the change without having your domain actually
                stop responding to email, etc.
                [Section 51]

G               Oh wow.. I didn't realize that Section 51 had the wrong name! 
                Before, it had a title for patching Tar to support BZip2 and
NOT 
                "Thoughts and procedures about Patching your distribution".
                Thanks to Chuck Hartley <[EMAIL PROTECTED]> for catching this.
                Regardless, its now section 52 to make room for the "Changing
                ISPs and/or IP addresses" section
                [Section 52]

----------------

G   07/02/00    Fixed all the broken links that were pointing to 
                http://www.ecst.csuchico.edu/~dranch/LINUX/TrinityOS-files
                They should have been pointing to TrinityOS-security.

N               Fixed all the "layed" spelling errors.  Thanks to 
                [EMAIL PROTECTED] for this one.

N               Removed the line from the TODO list:
                * Impliment external 10.x.x.x and 172.16-31.x.x packet
filtering
                [Section 2]

N               Added to the TODO list to modularize the rc.firewall rule set
so
                that users can update their firewall without having to re-edit
and 
                tailor it to their needs.
                [Section 2]

N               Fixed the formatting issues of the /etc/ftpconversions file
edit.
                Thanks to [EMAIL PROTECTED] for the sharp eye.
                [Section 7]

I               Updated the rc.firewall rule set to v3.60       

                # Added port 445 for Windows2000 CIFS / SMB filtering for both
INPUT and
                # OUTPUT. Also enhanced the informational section to explain
what each 
                # port does  

                # Added EXTENSIVE INPUT and OUTPUT filters for the IANA
reserved
                #     TCP/IP addressing scheme
                This one comes from good discussions with
[EMAIL PROTECTED]


                # - Added explicit though disabled Multicast filtering on the
extnernal    
                #   interface per many users requests.
                [Section 10]

I               Fixed a typo where the second CHMOD should have been for
                /home/chroot-dns-int and not ext.  

I               Updated the root-hints-update script to v2.1
                # v2.1 - Fixed a typo in the CHMOD of the external
root-hints.sb file
                #      - Fixed the file ownership of the internal root-hints.db
file
                #      - Changed the default path of where the new
root.hints.new file
                #        is to be placed
                #      - Updated to have a backup copy of the INTERNAL hints
file and not
                #        just have an EXTERNAL backup

N               Added a new subsection to get to the root-hints.db script
easier

                # A strong Thanks to [EMAIL PROTECTED] for these corrections
                [Section 24]

----------------

*C* 06/25/00    Updated the 2.2.x kernel section to remind users that 2.2.16 is
                and is the ONLY secure kernel version available.  See below.
                [Section 5]

*C*             Roughly June 7th, it was found that Linux running kernels less
                then 2.2.16 had a TCP exploit.  I have updated the rc.firewall
                to reflect this info:

                NOTE:  All 2.2.x Linux kernels prior to 2.2.16 have TCP exploit
that
                ****   that when combined with tools like Sendmail can leed to
a ROOT
                       compromise.  In addition to this, all kernels less than
2.2.11
                       have a fragmentation bug that renders all strong
IPCHAINS rule sets
                       void.  It is CRITICAL that users upgrade the Linux
kernel to at 
                       lease a 2.2.16+ kernel for proper firewall and system
security.
                [Section 10]

----------------

N       06/24/00        Added to the DNS section how to determine the version
of BIND
                                simply using "nslookup".
                                [Section 24]

----------------

G       06/22/00        Updated the /etc/logrotate.d/syslog file to reflect
that klogd
                        in /sbin and NOT /usr/sbin in RH 6.1  Thanks to for
catching
                        that [EMAIL PROTECTED]
                                [Section 8]

----------------
                                
N       06/19/00        Added a few options to the TrinityOS "Futures" section
                                        - Named compiling walk-thru
                                        - GnuPG / PGP support
                                [Section 3]

G                       Heavily went over the DNS section
                          - Cleaned up a lot of the text, fixed many formatting
and
                            and layout issues throughout this section, etc.
                          - Fixed two typos where the path for 212.0.200.100.db
and
                            192.168.0.db were pointing to chroot-ext and
chroot-int
                            instead of chroot-dns-ext and chroot-dns-int
                                [Section 24]

I                       It should be noted that as I mentioned above in the DNS

                        changes, I plan on going through all the various
TrinityOS 
                        section and cleaning out all the old formatting issues,
etc 
                        that were left over from the SGML port.  Though this
will take 
                        some time, TrinityOS will ultimately read and look
better.

                        It should also be mentioned that I'm in the process of
bringing 
                        up my new Linux box.  Since this machine is MODERN, I'm
updating 
                        TrinityOS to reflect the new changes in Linux such as
the hardware
                        map, Software RAID, as well as updated configurations
for 
                        Sendmail, etc. 

----------------

N       05/28/00    Updated the Getdate URL
                                [Section 5]

G                   Updated the IPCHAINS rule set to v3.59
                    #     - Fixed an error for the Squid re-direction where all

                    #       detination traffic was going to BROADCAST instead
of 
                    #       INTLAN.   Thanks to [EMAIL PROTECTED] for catching
this.
                    #
                    #     - Fixed an error where global SMTP allows on all 
                    #       interfaces were actually limited to the EXTIP
address.  
                    #       This should have been UNIVERSE.
                    #
                    #     - Fixed a typo where the AOL filtering example had
the 
                    #           SMTP port in destination and not the source
address 
                    #               field.
                    #       Thanks to [EMAIL PROTECTED] for these two reports.
                    [Section 10]

G                   Made some important updates to the DNS section:

                    - The in.addr file for the external DNS zone had the wrong
IP
                    address in it.

                    - Missed setting the chown ownerships for the external zone

                    directories.

                    Thanks to [EMAIL PROTECTED] for catching these.
                    [Section 24]

----------------

N       04/25/00        Ok, I've started to clean up the SGML code by hand.
Though 
                            Ian's Perl code did 95% of the work, it isn't as
pretty as
                            it should be.  

N                   I *DO* know that the PDF looks like crap.  I have a
possible
                    solution w/ the aid of the new version of GhostScript but
                    it will have to wait for a week or two.

N                   Some of the ASCII border art was mis-aligned.  I have
started
                    this cleanup but it will take some time to clean up all
issues.

N                   The CMOS setup table was mis-aligned.  Fixed.
                    [Section 4]

N                   Started to cleanup the formatting of this section.  You
will 
                    notice that the fixed sections DON'T have the "X" in front
                    of them (the old "checkmark" setup).

                    I also updated the 2.2.x kernel to be 2.2.14
                    [Section 5]

N                   Updated the URL of the TrinityOS security script
                    [Section 7]

N                   Fixed the formatting issues of the MASQ flowchart.
                    [Section 10]

G                   Fixed a typo where copying and then moving
/usr/sbin/named-ext
                    should have been named-xfer.  
                    Thanks to [EMAIL PROTECTED] for catching this.
                    [Section 24]

----------------

.----------------------------------------------------------------------------.
|  David A. Ranch - Linux/Networking/PC hardware         [EMAIL PROTECTED]  |
!----                                                                    ----!
`----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----'


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- 
THIS INCLUDES UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to