Chapter 16.
195
Controlling Access to Services
Maintaining security on your system is extremely important, and one approach for this task is to
manage access to system services carefully. Your system may need to provide open access to
particular services (for example,
httpd
if you are running a Web server). However, if you do not need
to provide a service, you should turn it off to minimize your exposure to possible bug exploits.
There are several different methods for managing access to system services. Choose which method
of management to use based on the service, your system's configuration, and your level of Linux
expertise.
The easiest way to deny access to a service is to turn it off. Both the services managed by
xinetd
and the services in the
/etc/rc.d/init.d
hierarchy (also known as SysV services) can be
configured to start or stop using three different applications:
Services Configuration Tool
This is a graphical application that displays a description of each service, displays whether
each service is started at boot time (for runlevels 3, 4, and 5), and allows services to be started,
stopped, and restarted.
ntsysv
This is a text-based application that allows you to configure which services are started at boot
time for each runlevel. Non-
xinetd
services can not be started, stopped, or restarted using this
program.
chkconfig
This is a command line utility that allows you to turn services on and off for the different runlevels.
Non-
xinetd
services can not be started, stopped, or restarted using this utility.
You may find that these tools are easier to use than the alternatives — editing the numerous symbolic
links located in the directories below
/etc/rc.d
by hand or editing the
xinetd
configuration files in
/etc/xinetd.d
.
Another way to manage access to system services is by using
iptables
to configure an IP firewall.
If you are a new Linux user, note that
iptables
may not be the best solution for you. Setting up
iptables
can be complicated, and is best tackled by experienced Linux system administrators.
On the other hand, the benefit of using
iptables
is flexibility. For example, if you need a customized
solution which provides certain hosts access to certain services,
iptables
can provide it for you.
Refer to
Section 43.8.1, “Netfilter and IPTables”
and
Section 43.8.3, “Using IPTables”
for more
information about
iptables
.
Alternatively, if you are looking for a utility to set general access rules for your home machine,
and/or if you are new to Linux, try the
Security Level Configuration Tool
(
system-config-
securitylevel
), which allows you to select the security level for your system, similar to the
Firewall
Configuration
screen in the installation program.
Refer to
Section 43.8, “Firewalls”
for more information.
Important
When you allow access for new services, always remember that both the firewall and
SELinux need to be configured as well. One of the most common mistakes committed
Содержание ENTERPRISE LINUX 5 - VIRTUAL SERVER ADMINISTRATION
Страница 22: ...xxii ...
Страница 28: ......
Страница 36: ...10 ...
Страница 40: ...14 ...
Страница 96: ...70 ...
Страница 116: ...90 ...
Страница 144: ...118 ...
Страница 146: ......
Страница 158: ...132 ...
Страница 165: ...Installing and Removing Packages 139 Figure 11 7 Installing and removing packages simultaneously ...
Страница 166: ...140 ...
Страница 172: ...146 ...
Страница 178: ......
Страница 228: ...202 ...
Страница 264: ...238 ...
Страница 318: ...292 ...
Страница 330: ...304 ...
Страница 388: ...362 ...
Страница 428: ...402 ...
Страница 452: ......
Страница 458: ...432 ...
Страница 476: ...450 ...
Страница 478: ...452 ...
Страница 494: ...468 ...
Страница 498: ...472 ...
Страница 530: ...504 ...
Страница 536: ...510 ...
Страница 544: ...Chapter 36 Log Files 518 Figure 36 7 Log file contents after five seconds ...
Страница 546: ......
Страница 550: ...524 ...
Страница 576: ......
Страница 584: ...558 ...
Страница 608: ......
Страница 776: ...750 ...
Страница 796: ...770 ...
Страница 800: ...774 ...
Страница 804: ......
Страница 806: ...780 ...
Страница 808: ...782 ...
Страница 816: ...790 ...
Страница 820: ...794 ...
Страница 822: ...796 ...
Страница 830: ...804 ...
Страница 836: ...810 ...
Страница 844: ...818 ...
Страница 848: ...822 ...