1 |
> 2008/12/21 Sadako <sadako@××××××××××××××.ca>: |
2 |
>>> I have one virtualbox using VT extensions, and runs fine. I have used |
3 |
>>> PaX in the guest with rsbac 1.3.7 and the noexec based on segmentation |
4 |
>>> and all others on (peMRXS flags) and goes fine (with pageexec does not |
5 |
>>> work, hangs at boot, so I switch segmexec). I think that you shouldn't |
6 |
>>> have any troubles with kvm, if you have some try using virtualbox. |
7 |
>>> I added -D_FORTIFY_SOURCE=2 to the cflags in make.conf compilation, it |
8 |
>>> runs fine too and I think is safe. Not hangs at the moment. |
9 |
>>> |
10 |
>>> 2008/12/16 Romain BERGE <romain.berge@×××××.com>: |
11 |
>>>> Hey all, |
12 |
>>>> |
13 |
>>>> I am wondering of using and AMD CPU with the AMD-V. |
14 |
>>>> I wonder of using KVM to virtualise a few Hardened server. |
15 |
>>>> |
16 |
>>>> Someone used already KVM+ Hardened ? |
17 |
>>>> |
18 |
>>>> Working fine ? |
19 |
>>>> |
20 |
>>>> Thanks |
21 |
>>>> |
22 |
>>>> Regards |
23 |
>>>> |
24 |
>>>> |
25 |
>>> |
26 |
>>> |
27 |
>> Do you actually have the virtualbox _host_ running under |
28 |
>> hardened-sources? |
29 |
>> If so, could you please upload your kernel config somewhere? |
30 |
>> |
31 |
>> I've been trying to do the same, but upon trying to boot a guest (any |
32 |
>> guest) via virtualbox the host box locks up, and I've tried everything I |
33 |
>> can think of, including disabling _all_ grsec and pax options within the |
34 |
>> kernel... |
35 |
>> |
36 |
>> |
37 |
>> |
38 |
> |
39 |
> Are you sure is related to the host?. Why?. |
40 |
> |
41 |
> |
42 |
It's the host box which is locking up, and the host which is running |
43 |
hardened-sources. |
44 |
Booting the host with gentoo-sources, and it works fine. |
45 |
|
46 |
I believe others have had the same issue as me, however there is at least |
47 |
one person who has had it working without any issues, see this fgo thread; |
48 |
https://forums.gentoo.org/viewtopic-t-713850.html |
49 |
|
50 |
Unfortunately, that user informed me via PM that he no longer has the |
51 |
kernel configs he used... |