> We will give "checksums" with our agents in our upcoming releases.
Checksums are useless if your install script is compromised, as well as if the server hosting the checksums is compromised. Signing everything while using an installer that verifies signatures (like yum, rpm and apt) is more secure, and just relies on you not losing control of your private key, instead of entire servers.
> Whenever you install SeaLion Agent, the most latest binary is installed. The agents in other servers are also updated, hence making them identical always.
Assuming your upgrade location is not compromised. Does your auto-updater check checksums or signatures, or does it rely on your servers always serving up the correct files? What if you push an auto-update that breaks servers?
curl -s https://agent.sealion.com | bash /dev/stdin $1 $2 $3 $4 $5 $6
> SeaLion agents are released after rigorous testing, to ensure we do not leave any security holes and features
No offense, but when I'm responsible for what happens on multiple servers I would like to ensure that myself, by checking the tcp payloads, endpoints connected to, files opened, etc. I'm certainly not alone in this.
> SeaLion agent requires Internet access to send data to its server. Hence internet access is mandatory.
Sending data can be accomplished individual firewall rules to whitelisted IPs. s3 is too broad of a target to allow unlimited access to.
> SeaLion agent works fine with SELinux in enforcing mode without any specific configuration.
Great!
> sudo /usr/local/sealion-agent/uninstall.sh
Not the best, but it seems to be clean.