* The security implications of NetWare on Linux
Let’s start off the week by taking a new look at Linux (I’m hoping Phil Hochmuth, who writes our Linux newsletter, won’t mind if we intrude on his domain. You probably should subscribe to his work, anyway – you’re going to need it soon.)
First the fun part: Novell CTO Alan Nugent was recently in Australia trying to pump up support for NetWare on Linux. He did give an interview to our fellow IDG publication, ComputerWorld Australia, and managed to come through it pretty well.
About The SCO Group and its mutterings, maunderings and malicious posturings, Nugent said the Linden, Utah company, “needs to put up, …or just cease.”
OK, so it’s not as pithy as it could have been, but Nugent’s a nice guy, and his meaning is clear. But when interviewer Julian Bajkowski asked if Novell regretted selling Unix to SCO, Alan put it into perspective when he replied, “…I guess the only thing I regret selling is my 1963 Corvette in 1968!”
Selling Unix was the right move for Novell at the time. Hindsight recriminations won’t solve problems. Nugent is an engaging and persuasive speaker, but he does have what many would consider a daunting task: convincing NetWare users that Linux servers are a better choice for their networks.
One thing that Alan didn’t address but something that Novell will need to face before very long is the issue of security. NetWare has had the reputation for many years, justly deserved, as the most secure operating system for network operations. It’s one of the reasons why NetWare became the leading operating system of the past 20 years. No one – not even the guy who writes the Network World Windows Networking Tips newsletter (that’s me) – could deny that NetWare security is far and away better than Windows security. Less well known, though, is that Linux (compared to NetWare) is almost as vulnerable as Windows.
The open source proponents will tell you that there are fewer problems and quicker fixes with Linux because the source code is subject to review by anyone wishing to look at the code. But this also means that any potential holes are exposed to would-be crackers early on in the development cycle. In 20 years of working with NetWare, I can only remember one significant security hole (GroupWise looks like Swiss cheese by comparison). That’s going to change, most likely, as Novell moves NetWare to the Linux kernel.
And not only will there most likely be more security problems, but fixing those problems may be beyond Novell’s control with open source software. There’s nothing to be afraid of, yet, but there’s a lot to be aware of in making this change to a new kernel.




