Rocky Linux 9 became generally available today, providing users of the open-source operating system with a series of security and performance updates. . Rocky Linux is based on the CentOS Linux operating system that is developed by Red Hat and is widely used in the cloud and on-premises to run enterprise applications. Since 2020 , Red Hat has no longer produced a full, freely available version of CentOS that is intended as an enterprise Linux distribution. Red Hat’s decision spawned a number of organizations, including the Rocky Enterprise Software Foundation (RESF) and Alma Linux , to create their own versions of CentOS. Among the primary supporters of the RESF is CIQ, which announced on May 11 that it had raised $26 million to help it grow its Rocky Linux efforts. . CentOS Stream 9 boosts stability and efficiency for business software, presenting a strong open-source alternative.. Rocky Linux, Enterprise Application, Security Enhancement, Performance Update, Open Source Solution. . LinuxSecurity.com Team
This LinuxSecurity.com article featured on the frontpage of Slashdot examines the concept of geo filtering and how it could add a valuable layer of security to your firewall , and explores how the Geolocation for nftables project is leveraging Open Source to provide intuitive, customizable geo filtering on Linux. . What if you could block connections to your network in real-time from countries around the world such as Russia, China and Brazil where the majority of cyberattacks originate? What if you could redirect connections to a single network based on their origin? As you can imagine, being able to control these things would reduce the number of attack vectors on your network, improving its security. You may be surprised that this is not only possible, but straightforward and easy, by implementing GeoIP filtering on your nftables firewall with Geolocation for nftables . . Geo filtering enhances Linux network security by restricting access based on location. Using nftables, admins can block foreign connections, enhancing safety.. GeoIP Filtering, Nftables Security, Network Defense. . Brittany Day
CrowdSec is (and will always remain) an open-source & free security solution able to analyze visitor behavior & provide an adapted response to all kinds of attacks. The solution also enables users to protect each other. Each time an IP is blocked, all community members are informed so they can also block it. . As of today, CrowdSec has users in more than 70 countries, who altogether blocked 120,000+ malicious IPs within 3 months, generating a real-time global IP reputation database. The tool was built for the people in order to make security accessible to everyone. The link for this article located at CrowdSec.net is no longer available. . CrowdSecure provides an accessible open-source defense mechanism that allows individuals globally to assess and mitigate harmful activities.. CrowdSec, IP Blocking, Community Defense. . LinuxSecurity.com Team
Linux has long had a close, working relationship with governments, but Lightweight Portable Security (LPS) is the first official U.S. Linux distribution.. Outside of the U.S., there are several The link for this article located at ZDNet Blogs is no longer available. . Explore the significance of Lightweight Portable Security, the pioneering Linux distribution designed for government applications in the United States.. Lightweight Portable Security, Government Distribution, Secure Linux, Cybersecurity Tool. . LinuxSecurity.com Team
Today, full-system encryption in software is feasible and practical. Here's how to get up and running using solutions from PGP, McAfee, Sophos, and open-source options TrueCrypt and DiskCryptor. There was a time, not all that long ago, when a fully-encrypted system disk was something only for people with money to burn. . You bought a special disk controller which performed hardware-based encryption, and then trusted the hardware vendor to make sure everything was implemented properly -- e.g., that they were using a good algorithm, that the key size for the encryption wasn't laughably short, and so on. Today, full-system encryption in software is both feasible and practical -- although how practical will depend on the workload involved. But it's not a security silver bullet, much as it might seem to be from the outside. It can, and does, add a layer of protection that greatly reduces the risk of data compromise in the event hardware is lost or stolen. But that protection depends entirely on how it's implemented, and whether or not the user's been educated in the way an encrypted system works. The link for this article located at Information Week is no longer available. . Explore robust strategies for complete drive encryption utilizing both commercial and community-driven applications to improve information safety.. full System Encryption, Software Encryption Options, Disk Encryption Best Practices, Open Source Encryption, Data Security. . LinuxSecurity.com Team
Port Knocking came about in around 2003, but it has various weaknesses. There are plenty of implentations though (some quite advanced). Most of the problems are fixed however by fwknop! fwknop stands for the . The link for this article located at Dark Reading is no longer available. . Explore the functionalities of Fwknop, a sophisticated port knocking solution that fortifies network defenses.. Fwknop Port Knocking, Network Security Tool, Authentication Methods, Open Source Security Solutions. . LinuxSecurity.com Team
While Microsoft's Active Directory (AD) is an effective play to circumvent the inherent central authentication foibles of Linux, getting the technology synced with servers has been a complex undertaking for IT practitioners, to say the least. Integrating with Windows eventually has to happen since there is no denying the majority. However, there are obvious open source secure solutions to authentication with Windows - LDAP and Kerberos along with a touch of Samba can go a long way in providing that type of solution. Read on for a devil's advocate's view of Linux authentication in a Windows environment - do you think these solutions match up to what Microsoft can put out? . The link for this article located at SearchEnterpriseLinux.com is no longer available. . Integrating Linux with LDAP, Kerberos, and Samba enhances authentication, enabling centralized management, strong security, and seamless AD compatibility across platforms. Linux Authentication, Active Directory Alternatives, Open Source Solutions. . LinuxSecurity.com Team
IPFire is a linux based firewall distribution with a lot of extras. The base for the stable version 1.4.9 was the IPCop that has been hardly modified. There were added: Asterisk PBX, Samba, MorningReconnect, LPR-NG and many other things. I've always been a fan of Shorewall and Firestarter - what have you used as a good base firewall setup? Any thoughts how this will match up in an enterprise server environment? . The link for this article located at Linux Mini is no longer available. . Delve into the fundamentals of IPFire, an effective firewall option tailored for residential and small-office/home-office (SOHO) environments, elevating your security configuration.. IPFire, Firewall Solution, Network Security, Home Security, Linux Distribution. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.