Gentoo Archives: gentoo-dev

From: Guido Bakker <guidob@g.o> (by way of Guido Bakker <guidob@g.o>)
To: gentoo-dev@g.o
Subject: Re: [gentoo-dev] grsecurity in default kernel
Date: Mon, 24 Dec 2001 06:15:50
Message-Id: 200112241315.27151.guidob@gentoo.org
1 As i see workstations, you don't offer remote shells, that would make it a
2 server already.. my hacked adsl modem with nat only allows sshd from the
3 outside... and sets state on sessions from the inside.. so when i want i can
4 ssh in, but that's just me... everything else is blocked from the internet...
5
6 i checked out grsecurity before and it looks promising, but the openwall
7 patch from solardesigner is nice as well.. what's best? i wouldn't enable it
8 standard as it can block certain things too...
9
10 just make it an option..
11
12 --
13 Guido
14
15 Ok, but i think grsecurity is something else. This seems to be a
16 user-mode application.
17
18 In my opinion you can enable grsecurity with some options on
19 workstation's, too.
20 Have you ever look at the new options from a grsecurity patched kernel.
21 What's could be against to make a workstation computer same secure as a
22 server?
23
24 Through the sysctl interface you could apply this to any kernel and
25 active the options
26 you want through a config-file and a init.d script i have posted some
27 days ago.
28 But I really think that all workstations could enable some options as
29 default.
30
31 Regards
32
33 Sebastian Werner
34
35 Am 24.12.2001 10:57:46, schrieb Guido Bakker <guidob@g.o>:
36 >I think it should be an option in the installer in the future...
37 >Security patches for a workstation have no use in my opinion...
38 >
39 >You could also look at the attachment which is from SUN...
40 >
41 >--
42 >Guido
43 >
44 >
45 >Hey
46 >
47 >i think it's nice to patch gentoo's default kernel with grsecurity
48 >(www.grsecurity.net). You integrate so many patches. Grsecurity enhance
49 >the security for the normal internet-user. I think it's a must in any
50 >default-kernel!
51 >
52 >Regards
53 >
54 >Sebastian Werner
55 >
56 >
57 >
58 >_______________________________________________
59 >gentoo-dev mailing list
60 >gentoo-dev@g.o
61 >http://lists.gentoo.org/mailman/listinfo/gentoo-dev