Summary

This spec defines an auditing aspect of the Ubuntu Hardened Team specified in HardenedUbuntu.

Rationale

The Ubuntu Hardened Team is made up of multiple sub-teams all approaching security from a different angle using a different set of tasks. One such important team is needed to audit for regressions in security features and for generally unfavorable conditions such as executable stacks.

Use cases

Scope

The scope for the Ubuntu Hardened Audit Team would follow the security features of Ubuntu Linux. Note that some of the features in this spec, such as PositionIndependentExecutables, are not yet in Ubuntu. We still describe how to handle them for informational purposes.

The Ubuntu Hardened Audit Team will responsibilities including the following:

Design

Somebody should probably write a bunch of documentation as they go along. Besides that, get a team together to do the above as below.

Implementation

The implementation is mostly flexible. Details on some things that could need to be done eventually are here.

Regressions:

Reporting:

Clean-Up:

Code

Data preservation and migration

Unresolved issues

BoF agenda and discussion


CategorySpec

HardenedUbuntu/Audit (last edited 2008-08-06 16:27:50 by localhost)