LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 07-12-2005, 05:18 AM   #1
Murdock1979
Member
 
Registered: Oct 2003
Distribution: Slackware Debian VectorLinux
Posts: 429
Blog Entries: 2

Rep: Reputation: 30
Security Updating


Hello All!

I recently got my Slackware configured and up and running fine. Now I must contend with maintenance.

My question is what is the easiest way to keep up to date with security issues. The Slackware site has daily security updates, but I simply do not have the time to follow up on each security problem.

Does Slackware have an auto-system like Debian and Windows that can ease the process of keeping the system secure?

Any suggestions will be appreciated.

Thank you,
Mords
 
Old 07-12-2005, 05:34 AM   #2
|2ainman
Member
 
Registered: Mar 2004
Distribution: Slackware current, DSL 0.9.2
Posts: 133

Rep: Reputation: 15
To me it seems like slackware hardly ever has massive amounts of security problems. Personally, I subscribe to the slackware-security mailing list ... so if I check my email and notice a security alert, I will read it, and if it affects my system I will ftp the new package and do an upgradepkg on it. You could also create a filter for messages from that mailing list only containing keywords pertaining to the critical services you run on your server or desktop, stuff thats accessible via the internet like ssh, apache, etc.

There are 3rd party utilities out there such as swaret and slapt-get which will upgrade your system fairly easily. Combined with a cron job it could result in little to no interaction. The only problem is that due to misconfiguration, user error, programmers error, or whatever, some of these utilites have been known to break a system. If you do decide to use one of these utilites, make sure you do your homework.
HTH
 
Old 07-12-2005, 07:32 AM   #3
Murdock1979
Member
 
Registered: Oct 2003
Distribution: Slackware Debian VectorLinux
Posts: 429

Original Poster
Blog Entries: 2

Rep: Reputation: 30
Thanks for the info.

So you're saying, that unlike Windows, I don't really need to be that concerned about updating my system so frequently?
 
Old 07-12-2005, 09:44 AM   #4
tuxrules
Senior Member
 
Registered: Jun 2004
Location: Chicago
Distribution: Slackware64 -current
Posts: 1,158

Rep: Reputation: 62
Quote:
So you're saying, that unlike Windows, I don't really need to be that concerned about updating my system so frequently?
If you see the security advisories on slackware site...they aren't many of them considering we are half way through the year. Also if you notice, most of them are related to applications that come with slackware (unlike windows) & not related to slackware itself. So if you are using those apps (like apache or php or mozilla), you should upgrade.

I generally use swaret but with lot of restrictions on it...i.e. no kernel upgrade and various other packages that I would not want to upgrade. This way I accidently don't ruin my system.

You can easily setup a cron job for swaret and it updates your system automatically or for a more controlled operation you can just instruct swaret via cron to just download packages, which you can install/upgrade manually later.

Subscribing to slackware security mailing list is what you should absolutely do.

Tux,
 
Old 07-26-2005, 06:42 PM   #5
uopjohnson
Member
 
Registered: Jun 2004
Location: San Francisco
Distribution: Slackware, Ubuntu, RHEL, OS X
Posts: 159

Rep: Reputation: 30
Maybe I'm off here... but what I do is rsync mirror the patches directory and then run an upgradepkg on that when there is a security advisory that affects my system. I suppose I could do this all via cron, but I like to know that is happening.
 
Old 07-26-2005, 06:57 PM   #6
tuxrules
Senior Member
 
Registered: Jun 2004
Location: Chicago
Distribution: Slackware64 -current
Posts: 1,158

Rep: Reputation: 62
Hey,

Have you heard of swaret or even slapt-get. I personally use swaret. It's an update utility and works flawlessly (at least for me). There's an argument as to which of the above two is better. I would not go into it...take a look at the websites and decide for yourself.

I haven't used slapt-get but you could setup swaret to update your system via cron. If you want more control, run swaret via cron so that i just fetches the newer packages when they are available and then you can manually go and update whichever affect your system. I would presume you could do the same with slapt-get.

Tux,
 
Old 07-27-2005, 10:44 PM   #7
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
i do like |2ainman, basically i just subscribed to the slackware-security mailing list and so whenever patrick releases a critical update i get an email letting me know... then i just download the updated package and do an upgradepkg on it... personally, i find this to be a simple and effective method for staying up to date, i have no plans on installing slapt-get, swaret, or any other automated system...

i also monitor secunia.com every day cuz sometimes i will make my own updated packages while i wait for patrick's...

Quote:
Originally posted by Murdock1979
The Slackware site has daily security updates, but I simply do not have the time to follow up on each security problem.
ummm, daily?? make sure you are monitoring the STABLE changelog and not the CURRENT one:

http://www.slackware.com/changelog/stable.php?cpu=i386

(the stable branch gets updates only when a critical problem is found, while the current branch gets all kinds of updates - which makes current non-suitable for mission-critical environments...)
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
help needed in security ,vonarabilities ,loopholes in linux security haseebnazar Linux - Security 2 11-23-2005 07:16 PM
[Security Questions] Last Login, how good is this feature for security breach info? t3gah Linux - Security 2 06-14-2005 01:02 AM
Updating security in Sarge King4lex Debian 12 09-07-2004 06:31 PM
todays requirements regarding security (not limited to linux security) markus1982 Linux - Security 8 04-25-2004 10:58 PM
Linux security Vs Windows security keene General 50 11-01-2003 11:22 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 09:24 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration