-
Notifications
You must be signed in to change notification settings - Fork 56
Closed
Description
Servers and workstations differ heavily, and there is no universal hardening that is also fine grained for both. A server is inherently a network. This package should prioritize workstations, as kicksecure is meant to be one. I do not support the idea of also being a server system. Firstly, some of hardening already eliminates the possibilty of kicksecure usage on specific server types, like a file sync or an email server might already face problems because of network hardening. They may have gone unnoticed, but this doesn't change the fact. The two reasonable options are:
- Primarily good option: Forget about servers, do not try to keep support for them universally. This strips us of a very very big area of possible hardening options. If we want to support both, in terms of security, we will be the "jack of all trades, master of none". Nothing would be hardened to its full extend in this case.
- Secondary, in my opinion the least favorable option, because of the unnecessary work it would require: Split this package in two. One package
security-misc-desktopand onesecurity-misc-server. At this point you can choose any other name you like.
But this has to be addressed in the near future, for the project to develop further.
Metadata
Metadata
Assignees
Labels
No labels