Red Hat Training
A Red Hat training course is available for Red Hat Enterprise Linux
章 13. 提升 Domain0 的安全性
When deploying Red Hat Virtualization on your corporate infrastructure, you must ensure that domain0 cannot be compromised. Domain0 is the privileged domain that handles system management. If domain0 is insecure, all other domains in the system are vulnerable. There are several ways to implement security you should know about when integrating Red Hat Virtualization into your systems. Together with other people in your organization,you should create a 'deployment plan' that contains the operating specifications and services that will run on Red Hat Virtualization, and what is needed to support these services. Here are some security issues to consider when putting together a deployment plan:
- 所執行的服務數量愈少愈好。您不會希望將太多的工作與服務加入 domain0。愈少物件在 domain0 上執行,安全性就愈高。
- 啟動 SeLINUX 來協助保全 domain0。
- 請利用防火牆來限制 domain0 的流量。您能夠以預設的拒絕規定來設置一道防火牆並且協助防止 domain0 受到攻擊。限制網路表面的服務其實也是很重要的。
- 請不要允許普通使用者存取 domain0。假如您允許普通使用者存取 domain0 的話,這可能會危及 domain0 的安全性而且讓它變得易受攻擊。請記得,domain0 是有特權的,假如授權給沒有特權的帳號可能會危害到並且降低安全性。