l i n u x - u s e r s - g r o u p - o f - d a v i s
L U G O D
 
Next Meeting:
October 20: Web Application Hacking: How to Make and Break Security on the Web
Next Installfest:
TBD
Latest News:
Oct. 10: LUGOD Installfests coming again soon
Page last updated:
2012 May 29 14:09

The following is an archive of a post made to our 'vox-tech mailing list' by one of its subscribers.

Report this post as spam:

(Enter your email address)
Re: [vox-tech] Ubuntu preseed issue
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [vox-tech] Ubuntu preseed issue



On 05/29/2012 11:58 AM, Jeff Newmiller wrote:
> I don't know anything about this, but...

	I suggest you take a good look at the
URL:https://help.ubuntu.com/community/InstallCDCustomization

>
> a) you really want to download a shell script and run it automatically as root? From such simple beginnings arise security disasters. Just build the script into your install, and update the install if it needs to change.
>

	The answer is yes!. It needs to be root to finish up the.
	Install. At the time it run you can not do a SUDO. You must be
	root.

	And seeing packages will be remove and other configuration files
	will be changed/added. all of the work needs to be done as root.

> b) If you must go there, I wonder whether the execute but has been set on the newly-downloaded file?


	In the post-install script you can do a 'su' to another user
	when dealing with non root issues.


	Now you do bring up a very great point. Trust and security. I
	would be very careful of using any preseed script. In fact you
	can confirm the preseed script is what you expect by using the
	MD5 sum at the time you specified the preseed file.

	BUT if you are using an in-house server to set-up a system while
	in-house then you can be freer about your usage. You can trust
	the set-up and know there is no man-in-the-middle.

	Debian Preseed is much like Red Hat Kickstart.

	I would say this would be a great topic for a LUGOD meeting. But
	without a car I would not be able to get from where I'm
	currently staying in the south bay up to a meeting in time.

							Tony
_______________________________________________
vox-tech mailing list
vox-tech@lists.lugod.org
http://lists.lugod.org/mailman/listinfo/vox-tech



LinkedIn
LUGOD Group on LinkedIn
Sign up for LUGOD event announcements
Your email address:
facebook
LUGOD Group on Facebook
'Like' LUGOD on Facebook:

Hosting provided by:
Sunset Systems
Sunset Systems offers preconfigured Linux systems, remote system administration and custom software development.

LUGOD: Linux Users' Group of Davis
PO Box 2082, Davis, CA 95617
Contact Us

LUGOD is a 501(c)7 non-profit organization
based in Davis, California
and serving the Sacramento area.
"Linux" is a trademark of Linus Torvalds.

Sponsored in part by:
Appahost Applications
For a significant contribution towards our projector, and a generous donation to allow us to continue meeting at the Davis Library.