Talk With an Expert

Aggressive Patching and the Use of a Standard Build: An OpenBSD Example

Aggressive Patching and the Use of a Standard Build: An OpenBSD Example (PDF, 1.92MB)Published: 05 Apr, 2002
Created by:
Michael Sullenszino

This paper starts with a brief general discussion of the importance of a standard build and defines Aggressive Patching as a vital part of defense in depth. It then goes on to demonstrate how to implement Aggressive Patching by creating a Standard Build internet server farm and support structures that allow for automated patching and rapid deployment of hardened servers. The general part of this paper is intended for anyone in the IT field who is interested in security in depth. The more hands-on part is aimed at System Administrators with some Unix background working for small to medium sized companies with an active internet presence. The system detailed in the pages below has been successfully deployed in a small ISP and a medium sized virtual web hosting company. The author's hope is that while this is OpenBSD specific, it can work as something of a general model for small to medium sized businesses to use.