Securing a system with limits.conf



I'm not sure if this is off-topic for linux-kernel but here it goes...

After doing some research (Googling, checking Hardening Linux, Essential System Administration and a number of other books) I was quite shocked that configuring the limits doesn't seem to be documented anywhere. Sure, they all list the information that can be acquired by ulimit -a or man limits.conf but those oneliner descriptions of options fail to describe:

- What does the setting actually limit (one can find what the data segment or a core file is by Googling but it would be nicer if the documentation listed the security implications of each setting).

- What is the scope of the limit: per-user, per-process, all descendants of the current process, ...?

- How should things be configured to reliably prevent non-priveleged users from DoS'ing a machine.

Is there possibly some documentation that I have not found or is there actually a huge gap in the essential security documentation here?

Thanks.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/



Relevant Pages

  • Re: Hard drive temperature: is 140°C normal ? (SAMSUNG SP1614N)
    ... > smartd reports stuff like: ... > googling to find out what is normal. ... I have no special cooling on the ... For lack of any documentation at samsungs web-site, ...
    (comp.os.linux.hardware)
  • Re: finally, a non-cretinous exposition of the Laryngeal theory
    ... documentation before I would spend any time on assertions arrived at ... after a few minutes of googling. ... that the languages in your country can't be usefully commented on by ... considering your feelings about Westerners doing "Margaret ...
    (sci.lang)
  • Re: Ubuntu (Linux); my first experience of...
    ... Exactly, there are thousands of pages of documentation, do you want somebody ... And do the googling? ... the program, but they were written by whatever Phd wrote the app, so ... get the Doze install on my dual-boot system fixed and get caught up on my ...
    (sci.electronics.design)
  • Re: Free memory level in 2.6.16?
    ... Hmmm, after a bit of googling and a download of 2.6.18, it seems that ... documentation on lowmem_reserve_ratio is still on the todo list. ...
    (Linux-Kernel)
  • Re: PIX 525 and SSL
    ... >configuring it. ... It appears the configuration guideance documentation is at ...
    (comp.dcom.sys.cisco)

Loading