i've got amazon ec2 instance running natty 11.04. want harden server , make sure it's secure handling sensitive data. i'm wondering should in /etc/apt/sources.list. can comment on these contents? or, better yet, recommend secure sources.list file?
code:## note, file written cloud-init on first boot of instance ## modifications made here not survive re-bundle. ## if wish make changes can: ## a.) add 'apt_preserve_sources_list: true' /etc/cloud/cloud.cfg ## or same in user-data ## b.) add sources in /etc/apt/sources.list.d ## c.) make changes template file /etc/cloud/templates/sources.list.tmpl # # see http://help.ubuntu.com/community/upgradenotes how upgrade # newer versions of distribution. deb http://us-west-1.ec2.archive.ubuntu.com/ubuntu/ natty main deb-src http://us-west-1.ec2.archive.ubuntu.com/ubuntu/ natty main ## major bug fix updates produced after final release of ## distribution. deb http://us-west-1.ec2.archive.ubuntu.com/ubuntu/ natty-updates main deb-src http://us-west-1.ec2.archive.ubuntu.com/ubuntu/ natty-updates main ## n.b. software repository entirely unsupported ubuntu ## team. also, please note software in universe not receive ## review or updates ubuntu security team. deb http://us-west-1.ec2.archive.ubuntu.com/ubuntu/ natty universe deb-src http://us-west-1.ec2.archive.ubuntu.com/ubuntu/ natty universe deb http://us-west-1.ec2.archive.ubuntu.com/ubuntu/ natty-updates universe deb-src http://us-west-1.ec2.archive.ubuntu.com/ubuntu/ natty-updates universe ## n.b. software repository entirely unsupported ubuntu ## team, , may not under free licence. please satisfy ## rights use software. also, please note software in ## multiverse not receive review or updates ubuntu ## security team. # deb http://us-west-1.ec2.archive.ubuntu.com/ubuntu/ natty multiverse # deb-src http://us-west-1.ec2.archive.ubuntu.com/ubuntu/ natty multiverse # deb http://us-west-1.ec2.archive.ubuntu.com/ubuntu/ natty-updates multiverse # deb-src http://us-west-1.ec2.archive.ubuntu.com/ubuntu/ natty-updates multiverse ## uncomment following 2 lines add software 'backports' ## repository. ## n.b. software repository may not have been tested ## extensively contained in main release, although includes ## newer versions of applications may provide useful features. ## also, please note software in backports not receive review ## or updates ubuntu security team. # deb http://us-west-1.ec2.archive.ubuntu.com/ubuntu/ natty-backports main restricted universe multiverse # deb-src http://us-west-1.ec2.archive.ubuntu.com/ubuntu/ natty-backports main restricted universe multiverse ## uncomment following 2 lines add software canonical's ## 'partner' repository. ## software not part of ubuntu, offered canonical , ## respective vendors service ubuntu users. # deb http://archive.canonical.com/ubuntu natty partner # deb-src http://archive.canonical.com/ubuntu natty partner deb http://security.ubuntu.com/ubuntu natty-security main deb-src http://security.ubuntu.com/ubuntu natty-security main deb http://security.ubuntu.com/ubuntu natty-security universe deb-src http://security.ubuntu.com/ubuntu natty-security universe # deb http://security.ubuntu.com/ubuntu natty-security multiverse # deb-src http://security.ubuntu.com/ubuntu natty-security multiverse
Forum The Ubuntu Forum Community Ubuntu Specialised Support Ubuntu Servers, Cloud and Juju Server Platforms [ubuntu] sources.list -- should i modify?
Ubuntu
Comments
Post a Comment