3.16. Security Level Selection

3.16.1. Standard Selection

Configure the services that will start when the system is activated. You can manually configure each service. In addition, you can configure security levels defined based on the purpose of each service to be started. The selectable security levels are as follows:

Table 3-6. Security levels

HighThe system will only start minimum services required to use the system as a client. This level ensures the highest security. This level is recommended for a computer that is directly connected to the Internet.
MediumIn addition to the high-level services, certain services, such as those from the SSH server and mail server (Postfix), will start.
OpenMost services will start. Many ports will be left open. This level ensures the use of various services, but the most dangerous in security. It should not be set for a machine that is connected to the Internet.

Usually, you should select "High", the default setting of the installer. On the [Custom Selection] tab, you can see services that can be activated at each security level. In addition, if you are a power user, you can manually configure each service.

If you select "Standard desktop", which is the default, as the installation type, the services that will be activated at the high and medium levels are as follows: The services that will be installed vary depending on the selected installation type.

Table 3-7. Services that will be activated at different security levels

Service nameHighMediumDescription
IIimYesYesIIIMP-based Input Method Server
UpdateCheckYesYesCheck script for updated packages
acpidYesYesACPI ¡ÊAdvanced Configuration and Power Interface¡Ë control daemon
alsasoundYesYesALSA sound driver load
apmdNoYesAPM (Advanced Power Management¡Ë control daemon
atapidmaYesYesATAPI CD-ROM DMA enable
clamdNoYesAnti-virus daemon
crondYesYesAutomatic program execution daemon
cupsYesYesCUPS printer server daemon
freshclamNoYesUpdate daemon for clam anti-virus DBs
fuseYesYesfuse kernel module load
keytableYesYesKeyboard layout configuration script
kparamYesYesKernel parameter configuration script
messagebusNoYesD-BUS daemon
netfsNoYesNetwork file system mount script
networkYesYesNetwork interface configuration script
postfixNoYesMail transfer agent
skkservNoYesSKK dictionary server
sshdNoYesSecure shell daemon
submountYesYessubfs enable
syslogYesYesSystem logging
tuneidendNoYesHard disk optimization
udevYesYesAutomatic device file generation
xinetdYesYesSuperserver

3.16.2. Custom selection

The services that will be activated when the system starts are selected. The numeric value in the "Securelevel" column is the security level defined for the service.

If "High", "Medium", or "Open" is selected on the [Standard selection] tab, the security level in this column is at least 80, 50, or 20, respectively, in the selected service. Select services to be started or stopped as required.

Tip

You can also use the service configuration tool to change the service activation configuration after Turbolinux FUJI is installed.