QUOTE
Description Bastille is a system hardening / lockdown program which enhances the security of a Unix host. It configures daemons, system settings and firewalls to be more secure. It can shut off unneeded services and r-tools, like rcp and rlogin, and helps create "chroot jails" that help limit the vulnerability of common Internet services like Web services and DNS.
If run in the preferred Interactive mode, it can teach you a good deal about
Security while personalizing your system security state. If run in the
quicker Automated mode, it can quickly tighten your machine, but not nearly
as effectively (since user/sysadmin education is an important step!)
If run in the preferred Interactive mode, it can teach you a good deal about
Security while personalizing your system security state. If run in the
quicker Automated mode, it can quickly tighten your machine, but not nearly
as effectively (since user/sysadmin education is an important step!)
Well I've installed it and run through the security prompts (and rebooted) on my CPanel/RHE3 server with no apparent problems. I didn't let it do anything that I thought might interfere with cpanel though... (like apache settings, etc) but the basic OS security stuff I let it tweak.
I've been waiting for Bastille to come out for RHEL 3 for a while now... it seems pretty neat... maybe a little less than what I was expecting... but it got into some security things that I didn't know about. So it's a good tool to tighten things up... an extra layer of defense.