Roadmap

Differences between revisions 73 and 74
Revision 73 as of 2009-05-06 23:37:13
Size: 7630
Editor: c-71-237-255-223
Comment:
Revision 74 as of 2009-05-25 14:32:06
Size: 6607
Editor: 80
Comment: fix up blueprint list
Deletions are marked like this. Additions are marked like this.
Line 11: Line 11:
=== Blueprints ===
 * https://blueprints.launchpad.net/ubuntu/+spec/jaunty-security-defaults
  * SHA512 '''Status: done'''
  * SYN-flood protection '''Status: done'''
  * Dovecot AppArmor profile '''Status: delayed -- need to integrate postfix too'''
  * dhclient AppArmor profile '''Status: done'''
  * Squid AppArmor profile '''Status: delayed -- needs more investigation'''
  * dhcpd AppArmor profile '''Status: done'''
  * firefox template AppArmor profile '''Status: started'''
  * ufw installer integration (debconf/preseeding only) '''Status: done''' (needs 0.27 for everything, but 0.26-0ubuntu1 has enable with common services)
 * https://blueprints.launchpad.net/ubuntu/+spec/use-pae-when-possible
  * have installer choose -server when hardware is PAE-capable (perhaps rename -server kernel to something that doesn't seem strange to desktop users).
  * related bugs:
   * https://launchpad.net/bugs/75157
   * https://launchpad.net/bugs/151942
  * '''Status: implementing via drop of i386 -server in J+1'''
 * https://blueprints.launchpad.net/ubuntu/+spec/64bit-pie-by-default
  * '''Status: delayed'''
=== Karmic Blueprints ===
Line 30: Line 13:
 * https://blueprints.launchpad.net/sprints/uds-karmic?searchtext=security-karmic

Jaunty

Hardened Compiler Flags

Karmic Blueprints

Documentation

  • The Security Team FAQ needs to be filled with answers to the various questions Ubuntu gets about security.

  • The Security Team KnowledgeBase need more to be written. Many ideas have already been listed there.

Investigations

Several ideas for possible work come from investigating existing the installed set of packages.

  • setuid: which programs are setuid and what may be needed to improve them.

  • measure how many bits of randomness are actually being used in kernel ASLR, compared to other ASLR implementations.
  • review ideas from brainstorm.

Unscheduled Wishlist Items

This area can be used to list ideas for future security work, or link to bugs that describe "Wishlist" issues.

Not Interested

  • hardened default config (Bastille-like). Check the compatibility of debian-bastille. Status: reviewed. what can be done in a default install is already being done


CategorySecurityTeam

SecurityTeam/Roadmap (last edited 2022-01-04 22:38:06 by rodrigo-zaiden)