Re: FreeBSD vs Linux for newbie?



Paul wrote:
I am considering a dedicated server hosted remotely. I am a developer. Although I get around on *nix boxes ok. I rarely install or configure apps.

I have a choice of FreeBSD and CentOS (which is basically Red Hat Enterprise without the branding).

Security is a HUGE factor to me but I need to be able to install and configure easily.

Which would you recommend and why?

Many thanks!



There is no real answer to this philosophical question, but:

You did not mention what you are doing, so we will assume it is a webapp. what are you using? mysql, postgresql, java, tomcat, jetty, perl, python, php, ruby?

If you go with a BSD flavor, the OpenBSD (openbsd.org) is "the most secure of the default installations"... but you don't get anything of much use without installing new packages, and "tainting" the security.

Linux would probably be the easiest for you to manage.

Use "yum" to install/update packages.

Setup iptables so that only the web server port is available to the public, and ssh is available only from your office/house.

If you write a poor web application, then one can break into any machine.


Alexander Spitzer
Bonsai Bonanza
http://www.BonsaiBonanza.com
.



Relevant Pages

  • The Big Ol Ubuntu Security Resource
    ... but its default install has flaws. ... are the mods you need to make to protect your system. ... If you've recently switched from Windows to the Linux distribution Ubuntu, ... IT Security has prepared a guide to help you ...
    (microsoft.public.windowsxp.general)
  • The Big Ol Ubuntu Security Resource
    ... but its default install has flaws. ... are the mods you need to make to protect your system. ... If you've recently switched from Windows to the Linux distribution Ubuntu, ... IT Security has prepared a guide to help you ...
    (microsoft.public.windowsxp.general)
  • Critical Alert Update - W32.Slammer
    ... PSS Security Response Team Alert - Update: ... SP2, and Microsoft SQL Desktop Engine Version (MSDE) 2000 RTM, Microsoft SQL ... and all applications that install Microsoft SQL Desktop ...
    (microsoft.public.sqlserver.security)
  • Critical Alert Update - W32.Slammer
    ... PSS Security Response Team Alert - Update: ... SP2, and Microsoft SQL Desktop Engine Version (MSDE) 2000 RTM, Microsoft SQL ... and all applications that install Microsoft SQL Desktop ...
    (microsoft.public.security)
  • [security bulletin] HPSBUX02108 SSRT061133 rev.14 - HP-UX Running Sendmail, Remote Execution
    ... SUPPORT COMMUNICATION - SECURITY BULLETIN ... This bulletin will be revised as other versions of Sendmail become available. ... install revision B.11.23.01.003 or subsequent, ... Security Bulletins via Email: ...
    (Bugtraq)