1 |
On Mon, 2008-12-29 at 17:05 -0800, Grant wrote: |
2 |
> >> What else would you recommend for me? |
3 |
> > |
4 |
> > I'd suggest to completely ignore the grsec (low/med/high) options and |
5 |
> > use the Hardened Gentoo level in the hardened-sources all the time. |
6 |
> > |
7 |
> > Xorg should not cause problems unless you are stuck using 3rd party |
8 |
> > binary drivers. Most of us are using a hardened X setup. |
9 |
> |
10 |
> Excellent, thank you. You think the "Hardened Gentoo (workstation)" |
11 |
> and "Hardened Gentoo (server)" grsecurity setups are adequate |
12 |
> low-maintenance solutions? |
13 |
|
14 |
|
15 |
Re: "low maintenance" |
16 |
I'm not sure we can dumb down the hardening efforts anymore than we |
17 |
already have. It's all pretty transparent and seems mostly like a normal |
18 |
install of anything else. The ELF's are just smarter. |
19 |
|
20 |
> What does a hardened profile do for my server? |
21 |
|
22 |
Enables things to match the kernel options/blocks things that conflict. |