Bug 1275695
| Summary: | MIscellaneous errors in Security Guide | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Kwan Lowe <kwan> |
| Component: | doc-Security_Guide | Assignee: | Robert Krátký <rkratky> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | ecs-bugs |
| Severity: | low | Docs Contact: | |
| Priority: | high | ||
| Version: | 7.3 | CC: | rhel-docs, tcapek |
| Target Milestone: | rc | Keywords: | Documentation |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2016-04-13 14:48:21 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1279970, 1279974 | ||
| Bug Blocks: | |||
|
Description
Kwan Lowe
2015-10-27 13:51:09 UTC
(In reply to Kwan Lowe from comment #0) Hi Kwan, Thank you for taking the time file his bug. I fixed the mistakes, provided explanation about other issues below, and finally opened other bugs to track the work on two of the more time-demanding issues. > Layout - Widowed title in PDF view Unfortunately, this is a known bug in our publishing tool. It cannot be helped from the content side. This applies to all widows in PDF. > 4.1 Desktop Security > > Word choice > > OLD: Of course, if the cracker starts an attack > NEW: Of course, if the attacker starts an attack In this context, this is the correct term. See https://en.wikipedia.org/wiki/Hacker_%28computer_security%29 > 4.2.4 > The method of installing screen to enforce session timeouts, though convenient, > is not necessarily best-practice. A similar effect can be had with setting the > bash or login shell TMOUT variable and setting the variable as read-only. > E.g., readonly TMOUT in the system-wide bash profile. Tracked in a separate bug: https://bugzilla.redhat.com/show_bug.cgi?id=1279970 > 4,2,5 > Typo in spacing. Also, the DOS example is probably not optimal. At the very > least, reinforce that all these configurations are close to moot if someone > has physical access and/or console access. What 'configurations'? The section talks about password-protecting GRUB. Is that what you mean? > 4.3.9.1 > See 4.4.1.1. Explicitly notes that prepending with 220 is not necessary. > This example should be fixed in the section rather than calling it out in a > note. The example is not wrong. 220 is the standard FTP response code for "Service ready for new user." I believe it makes sense to have it in the example as it is the custom, while mentioning that it's not required. > 4.4.1.1 > Example code adds 220 to beginning of each line. This is confusing to users > and specifically mentioned as unnecessary in other parts of the guide. See above. > 4.4.2 > Output listing spans more than a single page is difficult to read. Suggest > editing the output to only relevant lines that illustrate the concept. A > better example may be to pass the LISTEN directive to netstat by passing the > -l option: For example: netstat -tlnw. Additionally, the ss utility (part > of iproute) may be a better tool overall for this task. > [add ss usage examples] Tracked in a separate bug: https://bugzilla.redhat.com/show_bug.cgi?id=1279974 Hello Robert: Thanks for taking care of these. I debated the attacker/cracker for a bit, but agree that it's valid. For 4.2.5, I'm not sure what I was reporting :). I recall that there was a section on setting up a configuration to disable booting into DOS which would require console access. With console access, there's not much the system can do especially if the user can boot into an alternate OS. All the best, Kwan Closing. The separate bugs (#1279970, #1279974) will be used to track the outstanding issues. |