Uwe Trenkner
unread,Nov 28, 2022, 10:54:02 AM11/28/22Sign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to HardenedBSD Users
Dear all,
in 2019, I first used HardenedBSD on a production server. More servers
were added in the following years. But I recently migrated my last
server (back) to FreeBSD. I would like to use the opportunity to say
thank you to Shawn and the other project members and everyone with whom
I interacted on the mailing list.
I would like to explain why I have moved away from HardenedBSD. Please,
do not read it as an attack on the project or anyone in particular!
When I first used HardenedBSD it was out of a belief that it would make
my server more secure and also easier to maintain (at that time we had
very frequent patches to FreeBSD’s base system due to software such as
OpenSSL and NTPd, both of which were replaced by HardenedBSD through
saner alternatives). I also hoped that HardenedBSD would become the
testbed for new security features that would later be included in
FreeBSD. However, first the project had to bid farewell to LibreSSL due
to lack of manpower. And then I found out more and more that updating
HardenedBSD was somewhat of an adventure, e.g. would the new kernel play
with the secadm kernel module? Or would the server stop booting because
of incompatability. Updating the operating system or packages also
required (more) downtime because of secadm as it prevents the unlinking
of certain files. And several times I (and others) found out that some
port did not build anymore on a new HardenedBSD version. Sometimes, I
found out in advance via the mailing list, sometimes I ran into trouble
myself. As a result, I often found myself postponing necessary updates.
I began with the 11 branch, but that was silently phased out. I think
updates stopped for something like ¾ year before the end of the official
support was announced, again due to lack of manpower. The main servers
of the project had to be moved to new locations several times since
2019, sometimes resulting in weeks of downtime and no updates.
Overall, my two hopes/expectations have not come true: HardenedBSD has
not made my admin life easier. And unfortunately, I do not see FreeBSD
picking up on the security solutions developed by the HardenedBSD
project. The differences between the two operating systems seem to get
bigger and bigger, sometimes leading to additional built problems on the
part of HardenedBSD.
I absolutely see value in HardenedBSD and I am thankful for the work you
all put into it. But for my use cases, it does not feel like the best
solution. That’s why I am saying farewell. I just sent another donation
to the HardenedBSD project and wish you all the best.
Kind regards
Uwe