next up previous
Next: Changing Your Root Password Up: Inessential Linux-Athena Previous: Running FTP and HTTP

Security

By now, you probably have a Linux machine which is on MITnet (and hence the Internet). One thing every person running a Unix machine on some network should note is that Unix and the network are probably both insecure. In general, Unix machines that are newly bought or newly set up are notoriously insecure. They are probably vulnerable to any number of attacks. RedHat-Athena should be relatively safe, but there are still some things you should probably do, such as adding yourself to the netusers mailing list (blanche netusers -a $USER) and reading the discuss meeting bloom-picayune:/usr/spool/discuss/linuxch-alert. Another good source for information about security holes in RedHat Linux is the WWW page http://www.redhat.com/support/docs/rhl/rh40-errata-general.html. (This page also contains information about other problems which RedHat Linux 4.0 may have.)

One other very important issue is configuring your machine to support secure telnets. After installation, your machine will accept incoming telnets; however, they will not be encrypted! This means that if you log in and type your password, you will be transmitting your password in clear text over the network! This means that anyone who is on the physical network(s) that your password is transmitted through will be able to obtain your password, if they are sufficiently motivated and knowledgeable.gif

In order to support secure incoming telnets, you need what is called a srvtab. This file contains a secret key which allows your machine to authenticate incoming users to Kerberos and then encrypt the connection. In order to get this file, send mail to accounts asking for one; be sure to include both your username and your computer's hostname in the message. You should receive a response three to five days later telling you how to retrieve the file. You should install it in /etc/athena/srvtab and execute

chown root.root /etc/athena/srvtab
chmod 400 /etc/athena/srvtab
/usr/athena/bin/ksrvutil change
Your srvtab should start working in a day or two. If you require more assistance, send mail to net-help.

Remember that it is important to keep your system secure; if unauthorized users gain access to your machine, they may be able to damage your data and the data of other users of your system (including data stored on Athena accounts).




next up previous
Next: Changing Your Root Password Up: Inessential Linux-Athena Previous: Running FTP and HTTP

Aaron M. Ucko
Sun Aug 3 09:48:16 EDT 1997