Secure Server Distro
- by Drama
Hello,
I have a root-server (i7/24GB/1TB) running Ubuntu 10.04 LTS as my OS. After some security audits (OpenVAS, Retina etc) I see that Ubuntu isn't the most secure system for a semi-corporate environment. Its updated from many sources, ofc from the Ubuntu security repo too.
But nevertheless I could exploit my OpenSSL install with an exploit from August/September.
There are some critical updates needed which Ubuntu does not provide.
I was using Debian and Ubuntu for almost 5 years but now I doubt.
What distro is secure and up to date from your point of view? How can I make the server more secure? Outsourcing of every software-module to a VM?
I am not new to server-hardening, my packages are up to date I read Ubuntu Security Notices and I have no unneeded services installed on my server.
Thanks.