[ale] Server Install

Allen, responses in-line


On Jun 29, 2010, at 11:53 PM, George Allen <glallen01 at gmail.com> wrote:

> 1) Is there a bare-bones version of RHEL/Centos that is the equivalent
> of a 'server' or 'jeos' install? I did a Centos 5.5 install the other
> day, picked only the "server task" (to put it in debian terms) and
> still came out with a 2gig install. I'll try again without selecting
> anything and see what it comes down to.

If you don't select anything in the package install you'll still get GNOME and X, plus a bunch of standard apps like Firefox.  It sounds like you want, on the installer package selection screen, to "Customize" your packages.  If you're doing more than one or two boxes the same way, you'll want to use kickstart to automate the installation.  There is a chapter in the Red Hat Installation Guide on Kickstart available from http://www.redhat.com/docs

> 2) What is the best way to manage application of "configuration
> items." There are the standard version control systems to track
> changes. But I'd like something that can manage OS configuration items
> based on a policy document. Maybe puppet, bastille, or cfengine? I'll
> read up on each of these, but what do you suggest?

I use puppet, and have been quite happy.

> 3) We get re-digested forms of CVEs that we're told to check and prove
> compliance with. Our windows shop has this system in place with tools
> that can read the XML of these alerts, execute scripts to test against
> them (on windows), and then generate another report of compliance. We
> will 

I was a little too happy with the delete there, stupid phone!  But to answer your question, I've not seen anything that does what you want, though I've not looked that hard.  All the fixed CVEs are listed in an RPMs changelog, so if you have the CVE number, you could grep the changelog for it.  If the CVE is there, it's fixed, if not, you need to find, or wait for, an update.

