From mboxrd@z Thu Jan 1 00:00:00 1970 From: Joshua Branson Subject: Adding a section about security in the guix manual Date: Wed, 09 Jan 2019 09:52:53 -0500 Message-ID: <87va2xc27u.fsf@dismail.de> Mime-Version: 1.0 Content-Type: text/plain Return-path: Received: from eggs.gnu.org ([209.51.188.92]:50955) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ghFE5-0007ZL-AK for guix-devel@gnu.org; Wed, 09 Jan 2019 09:53:05 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ghFE4-0004Mc-F3 for guix-devel@gnu.org; Wed, 09 Jan 2019 09:53:01 -0500 Received: from dismail.de ([78.46.223.134]:25686) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1ghFE3-0004Gs-SY for guix-devel@gnu.org; Wed, 09 Jan 2019 09:53:00 -0500 Received: from dismail.de (localhost [127.0.0.1]) by dismail.de (OpenSMTPD) with ESMTP id fc2db96e for ; Wed, 9 Jan 2019 15:52:56 +0100 (CET) Received: from smtp1.dismail.de (10.240.26.11 [10.240.26.11]) by mx1.dismail.de (OpenSMTPD) with ESMTP id d69a1a91 for ; Wed, 9 Jan 2019 15:52:56 +0100 (CET) Received: from smtp1.dismail.de (localhost [127.0.0.1]) by smtp1.dismail.de (OpenSMTPD) with ESMTP id 5f7163b9 for ; Wed, 9 Jan 2019 15:52:56 +0100 (CET) Received: by dismail.de (OpenSMTPD) with ESMTPSA id 796c90e4 (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256:NO) for ; Wed, 9 Jan 2019 15:52:55 +0100 (CET) List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: guix-devel@gnu.org Hello, I would like to store many of the ideas from this arch wiki page about security into the guix manual. https://wiki.archlinux.org/index.php/Security Perhaps I would put it right after GNU Distribution > System Configuration. Perhaps I would call that section "Hardening Recommendations". Some of the things that I want to include are strong passwords, encrypted drives, MAC, kernel hardening (which we currently don't have a linux-libre-hardened do we?), sandboxing applications, firewalls, and physical security. I may not be able to complete this project swiftly, but I do intend to put it on my TODO list. Is there something else I should add or that I am missing? Thanks, Joshua -- Joshua Branson Sent from Emacs and Gnus