Gentoo Archives: gentoo-hardened

From: Panagiotis Atmatzidis <p.atmatzidis@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Obtaining a Xen/SELinux/PaX/GRSecurity kernel
Date: Sun, 14 May 2006 11:26:27
Message-Id: 44671405.8020007@gmail.com
In Reply to: Re: [gentoo-hardened] Obtaining a Xen/SELinux/PaX/GRSecurity kernel by "Peter S. Mazinger"
1 Peter S. Mazinger wrote:
2 > On Sun, 7 May 2006, Alex Efros wrote:
3 >
4 >> Hi!
5 >>
6 >> On Sun, May 07, 2006 at 12:28:40AM -0400, Kevin wrote:
7 >>> If I wanted all four of the Xen/SELinux/PaX/GRSecurity patch sets
8 >>> incorporated into a kernel, any recommendations for doing this?
9 >> AFAIK hardened-sources already contain SELinux+PaX+GRSecurity.
10 >
11 > I would say hardened-sources have either SELinux-PaX or PaX/GRSecurity
12 >
13 > Peter
14 >
15
16 Yes and it's a good practice to keep the security models separated even
17 on ml posts. I was a bit confused myself at the beginning and I found
18 many users who are confused even though they use one of the security
19 models mentioned above. Many people think that they can use rsbac +
20 grsecurity + SELinux all together, which in theory[1] is possible but it
21 makes no sense and turns the box into something unusable.
22 So, be nice with newcomers and try not to confuse them :-)
23
24
25 [1] A guy told me that he installed all the 3 sec models in his test box
26 once upon a time.
27 --
28 gentoo-hardened@g.o mailing list