Open main menu

OpenVZ Virtuozzo Containers Wiki β

Editing Security

Warning: You are not logged in. Your IP address will be publicly visible if you make any edits. If you log in or create an account, your edits will be attributed to your username, along with other benefits.

The edit can be undone. Please check the comparison below to verify that this is what you want to do, and then save the changes below to finish undoing the edit.
Latest revision Your text
Line 1: Line 1:
For a project such as OpenVZ, security of the software is of paramount importance. Let's explain how we assure that OpenVZ is secure.
+
For a project such as OpenVZ, security of the software is of paramount importance. This is how we assure that OpenVZ is secure.
  
 
== Kernel ==
 
== Kernel ==
 
 
The OpenVZ kernel is based on the Linux kernel. The OpenVZ team tracks and analyzes all the security updates to the Linux kernel and applies them accordingly.
 
The OpenVZ kernel is based on the Linux kernel. The OpenVZ team tracks and analyzes all the security updates to the Linux kernel and applies them accordingly.
  
To achieve the maximum possible security and stability, stable OpenVZ kernels are based on Red Hat Enterprise Linux kernels, which are conservative and well-maintained. By using an enterprise kernel as a base (rather than latest vanilla kernel), we avoid adding new bugs or security holes, still the old ones are getting discovered and fixed, and the kernel matures.
+
Note that the current stable kernel branch is based on the 2.6.18 kernel, which is quite old. This is done to achieve the maximum possible security and stability. By using an older kernel, we avoid adding new bugs or security holes, but the old bugs and holes are getting discovered and fixed, and the kernel matures. Big vendors such as Novell and Red Hat do the same for their enterprise Linux offerings: for example, Red Hat Enterprise Linux 4 is based on kernel 2.6.9.
  
 
== Audit ==
 
== Audit ==
 
+
OpenVZ has undergone a thorough security audit, performed by Solar Designer in winter 2005. He found a single issue in OpenVZ kernel code and a couple of issues in mainstream Linux kernel code — all of them were fixed, and the mainstream fixes were sent to the LKML.
OpenVZ has undergone a thorough security audit, [https://lists.openvz.org/pipermail/users/2015-October/006563.html performed by Solar Designer] in winter 2005. He found a single issue in OpenVZ kernel code and a couple of issues in mainstream Linux kernel code — all of them were fixed, and the mainstream fixes were sent to the LKML.
 
  
 
[[Category: Security]]
 
[[Category: Security]]
 
[[Category: Kernel]]
 
[[Category: Kernel]]

Please note that all contributions to OpenVZ Virtuozzo Containers Wiki may be edited, altered, or removed by other contributors. If you don't want your writing to be edited mercilessly, then don't submit it here.
If you are going to add external links to an article, read the External links policy first!

To edit this page, please answer the question that appears below (more info):

Cancel Editing help (opens in new window)