 OpenBSD runs on many different hardware platforms.  OpenBSD is thought of by many security professionals to be the most secure UNIX-like operating system.

Slides:



Advertisements
Similar presentations
Software change management
Advertisements

1 Dynamic DNS. 2 Module - Dynamic DNS ♦ Overview The domain names and IP addresses of hosts and the devices may change for many reasons. This module focuses.
Windows Deployment Services WDS for Large Scale Enterprises and Small IT Shops Presented By: Ryan Drown Systems Administrator for Krannert.
Content Overview Update Process Additional Tools.
14.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft Windows Server 2003 Active Directory Infrastructure.
(NHA) The Laboratory of Computer Communication and Networking Network Host Analyzer.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 7: Planning a DNS Strategy.
Chapter 12 Reading assignment n From “Running Linux”, on reserve at PSU Main library (2-hour checkout) Chapter 1 (pages 1 through 41)Chapter 1 (pages 1.
Patching MIT SUS Services IS&T Network Infrastructure Services Team.
Overview Basic functions Features Installation: Windows host and Linux host.
Cambodia-India Entrepreneurship Development Centre - : :.... :-:-
MCTS Guide to Microsoft Windows Server 2008 Network Infrastructure Configuration Chapter 2 Installing Windows Server 2008.
Installing software on personal computer
SharePoint Portal Server 2003 JAMES WEIMHOLT WEIDER HAO JUAN TURCIOS BILL HUERTA BRANDON BROWN JAMES WEIMHOLT INTRODUCTION OVERVIEW IMPLEMENTATION CASE.
Installing Samba Vicki Insixiengmay Jonathan Krieger.
Hands-On Microsoft Windows Server 2008 Chapter 1 Introduction to Windows Server 2008.
Module 1: Installing Windows XP Professional. Overview Manually Installing Windows XP Professional Automating a Windows XP Professional Installation Using.
Module 7: Configuring TCP/IP Addressing and Name Resolution.
© Paradigm Publishing Inc. 4-1 Chapter 4 System Software.
About the Presentations The presentations cover the objectives found in the opening of each chapter. All chapter objectives are listed in the beginning.
MCTS Guide to Microsoft Windows Server 2008 Applications Infrastructure Configuration (Exam # ) Chapter Two Deploying Windows Servers.
SSI-OSCAR A Single System Image for OSCAR Clusters Geoffroy Vallée INRIA – PARIS project team COSET-1 June 26th, 2004.
Computers Are Your Future Eleventh Edition Chapter 4: System Software Copyright © 2011 Pearson Education, Inc. Publishing as Prentice Hall1.
Chapter 4 System Software.
©Kwan Sai Kit, All Rights Reserved Windows Small Business Server 2003 Features.
Promoting Open Source Software Through Cloud Deployment: Library à la Carte, Heroku, and OSU Michael B. Klein Digital Applications Librarian
Three steps to sell Office Always ask every customer the following questions to get them interested in buying Office: Did you know that Office.
Microsoft Active Directory(AD) A presentation by Robert, Jasmine, Val and Scott IMT546 December 11, 2004.
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
DCE (distributed computing environment) DCE (distributed computing environment)
Guide to Linux Installation and Administration, 2e1 Chapter 2 Planning Your System.
Chapter 4 System Software. Software Programs that tell a computer what to do and how to do it. Sets of instructions telling computers to perform actions.
Windows 2003 Installation/Upgrade and Update. Checking Compatibility Supported Upgrade paths Using the MS Windows Upgrade Advisor HCL (Hardware Compatibility.
1 Capstone Presentation Team Fugu and the OpenBSD Tools Project.
Computer Emergency Notification System (CENS)
Samba – Good Just Keeps Getting Better The new and not so new features available in Samba, and how they benefit your organization. Copyright 2002 © Dustin.
CS Capstone OS Tools for OpenBSD Overview Presentation Team Fugu.
Microsoft Management Seminar Series SMS 2003 Change Management.
Berkeley Software Distribution
DNS DNS overview DNS operation DNS zones. DNS Overview Name to IP address lookup service based on Domain Names Some DNS servers hold name and address.
Page 1 Printing & Terminal Services Lecture 8 Hassan Shuja 11/16/2004.
© Paradigm Publishing, Inc. 4-1 Chapter 4 System Software Chapter 4 System Software.
Rob Davidson, Partner Technology Specialist Microsoft Management Servers: Using management to stay secure.
Linux Operations and Administration
Hands-On Virtual Computing
an free source operating system
R. Krempaska, October, 2013 Wir schaffen Wissen – heute für morgen Controls Security at PSI Current Status R. Krempaska, A. Bertrand, C. Higgs, R. Kapeller,
STAAR Assessment Management System and StAAR Online Testing Platform
© N. Ganesan, Ph.D., All rights reserved. Windows Server Installation Nanda Ganesan, Ph.D.
2: Operating Systems Networking for Home & Small Business.
Automating Installations by Using the Microsoft Windows 2000 Setup Manager Create setup scripts simply and easily. Create and modify answer files and UDFs.
By the end of this lesson you will be able to: 1. Determine the preventive support measures that are in place at your school.
OPERATING SYSTEMS (OS) By the end of this lesson you will be able to explain: 1. What an OS is 2. The relationship between the OS & application programs.
© N. Ganesan, Ph.D., All rights reserved. Windows Server Installation Nanda Ganesan, Ph.D.
Operated by Los Alamos National Security, LLC for NNSA U N C L A S S I F I E D Slide 1 Windows Desktop Deployment Service at LANL Mark Wingard Central.
1 Remote Installation Service Windows 2003 Server Prof. Abdul Hameed.
Canadian Bioinformatics Workshops
Let's talk about Linux and Virtualization in 'vLAMP'
Create setup scripts simply and easily.
Building and Testing using Condor
CompTIA Linux+ Powered by LPI 2 LX0-104 Dumps PDF LX0-104 Dumps LX0-104 Braindumps LX0-104 Question Answers LX0-104 Study Material.
Printer Admin Print Job Manager
Dev Test on Windows Azure Solution in a Box
20409A 7: Installing and Configuring System Center 2012 R2 Virtual Machine Manager Module 7 Installing and Configuring System Center 2012 R2 Virtual.
IS3440 Linux Security Unit 7 Securing the Linux Kernel
SUSE Linux Enterprise Desktop Administration
PLANNING A SECURE BASELINE INSTALLATION
Mark Quirk Head of Technology Developer & Platform Group
IT Management, Simplified
Presentation transcript:

 OpenBSD runs on many different hardware platforms.  OpenBSD is thought of by many security professionals to be the most secure UNIX-like operating system as the result of a never-ending comprehensive source code security audit.  OpenBSD is a full-featured UNIX-like operating system available in source form at no charge.  OpenBSD integrates cutting-edge security technology suitable for building firewalls and private network services in a distributed environment.  OpenBSD benefits from strong ongoing development in many areas, offering opportunities to work with emerging technologies with an international community of programmers and users. Our client is migrating many of their systems to OpenBSD, because they have found it to be a better match for their needs in many areas of work. Until now, however, they were missing two tools available on other systems: an Automated Installer and an Automated Patcher These tools have been holding them back somewhat in their adoption of OpenBSD. This is where we come in. This semester, we have built these tools by extending already existing projects to meet our client’s requirements. Using these tools, the administrators will save time, keep their systems more consistent, and keep security patches up-to-date. The OS Tools Project Ben Atkin –Communicator and Researcher Thad Boyd –Facilitator and Webmaster Team Fugu Members Nauman Qureshi –Recorder and Documenter Erik Wilson –Team Leader and Organizer Our Client Ernest Bowman-Cisneros and Margaret Johnson (System Administrators) USGS Astrogeological Division - Flagstaff, AZ Our client works at one of the largest research stations in the country for space exploration and mapping. They have participated in many high-profile projects Including the Spirit and Opportunity rovers. Their space photography, mapping, and research efforts make heavy demands on computing infrastructure. To manage a large number of servers, they have learned to work efficiently and make use of the latest and greatest system administration tools. for the United States Geological Survey Astrogeology Division Team Fugu and the OpenBSD Tools Project About OpenBSD OpenBSD is a free UNIX variant, comparable to Linux, but designed with security as the main goal. In fact, other free UNIX distributions use security tools that are part of the OpenBSD project, most notably OpenSSH.

Automated InstallerAutomatic Patcher Boot system Answer Question(s) Reboot into installed system =20+ minutes/computer Standard (Interactive) Installer Create configuration file Boot system Reboot into installed system =10 minutes work for a group of computers Automated Installer Wait for automated install to finish Wait Configuration File Sections GeneralBehavior, Pre- and Post-Install Scripts NetworkNetwork Configuration (hostname, address, subnet) DisksDisk Geometry FilesetsProgram archives to download and install FinalFinal configuration settings such as time zone Single configuration file can be applied to systems with different brands of hardware and different disk geometry File can be loaded from disk or network User can interrupt installer and override option specified in the configuration file Internet monitoring available Overview Tepatche::Source +download_src(): bool +apply_src_patch(): bool Tepatche::Binary +apply_bin_patch(): bool +create_bin_patch(): bool +make_psuedo_tree(): bool Tepatche::Main +main() +read_config() +download_patches() Added features to Tepatche project created by Gunnar Wolf at UNAM (Universidad Nacional Autonoma de México) Ability to create binary patches Ability to install binary patches Split patcher into modules (diagram above) Overview Automatic patcher downloads and installs security updates Security updates are released as issues are discovered Important part of a secure system Work Completed Based on existing OpenBSD installer Operates automatically, greatly increasing efficiency Features Reads configuration options from a file Binary Patching Before we added binary patching, all that was available was source patching. Source patching requires that patches be compiled into machine code on each computer. Compiling can take the system hours of time. While it’s compiling, the full performance of the computer is not available. Binary patching allows the code to be compiled once, on an administrator computer, and then transferred in binary (machine code) form to the other computers. This helps keep the researchers’ servers and workstations to be responsive at all times.