> I'd like to comment, that what we're looking for now is the people to
> have root accounts on mphq. IMO this requires some deep knowledge,
> since there will hopefully be several chroot/qemu/usermode linux
> virtual environments inside the main server isolating everything to
> make a compromise basically impossible in principle and also make the
> effect of any possible compromise negligible.

Actualy, no. The first thing the newly formed team has
to decide on, is how the machine should be installed.
Vritual servers are one possibility that has been discussed,
but it is up to the team to decide.

Anyways, any concidered solution has to fullfill 3 criteria:
* Secure enough so any break in is unlikely
* Does not restrict the regular users too much
* Can be handled by the admin team

Of course, these are abolutely subjective and
cannot be measured in hard numbers.

			Attila Kinali


