1 |
Hi Genco, |
2 |
|
3 |
I have just been discussing an AMD64 hardened build on this ML, and what |
4 |
I was advised to do was to build the system with the standard profile |
5 |
(../profiles/default-linux/amd64/2005.0/no-multilib/) and the hardened |
6 |
use flag. |
7 |
|
8 |
Then, once the system is up and running to use this guide to convert |
9 |
your system to selinux: |
10 |
|
11 |
http://www.gentoo.org/proj/en/hardened/selinux/selinux-amd64-handbook.xml?part=2&chap=0 |
12 |
|
13 |
If you are using x86 system, then you should be able to use a standard |
14 |
livecd with the selinux-stage3 tarball, and follow this guide: |
15 |
|
16 |
http://www.gentoo.org/proj/en/hardened/selinux/selinux-x86-handbook.xml |
17 |
|
18 |
or you could install a standard system with stage3 and convert it |
19 |
|
20 |
http://www.gentoo.org/proj/en/hardened/selinux/selinux-x86-handbook.xml?part=2&chap=0 |
21 |
|
22 |
Hope this helps, and please forgive me if I'm off the mark somewhere! |
23 |
|
24 |
Cheers, |
25 |
Chris |
26 |
|
27 |
Genco YILMAZ wrote: |
28 |
|
29 |
> Many thanks , |
30 |
> I it more clear than before now. |
31 |
> |
32 |
> regards. |
33 |
> |
34 |
> |
35 |
> Dan Gregory wrote: |
36 |
> |
37 |
>> Chris PeBenito wrote: |
38 |
>> |
39 |
>> |
40 |
>>> On Mon, 2005-04-04 at 17:17 +0300, Matan Peled wrote: |
41 |
>>> |
42 |
>>> |
43 |
>>> |
44 |
>>>> Genco YILMAZ wrote: |
45 |
>>>> |
46 |
>>>> |
47 |
>>>> |
48 |
>>>>> hi, |
49 |
>>>>> I would like to install a new SElinux gentoo for a production server |
50 |
>>>>> but I am a littled bit confused. |
51 |
>>>>> SELinux livecd is located under experimental directory in gentoo |
52 |
>>>>> mirrors. Is it safe to use |
53 |
>>>>> SELinux gentoo for a production server when it is properly |
54 |
>>>>> configured? |
55 |
>>>>> |
56 |
>>>>> thanks. |
57 |
>>>>> |
58 |
>>>> |
59 |
>>>> The LiveCD is expermintal, but Gentoo's SELinux support is pretty |
60 |
>>>> stable. |
61 |
>>>> |
62 |
>>> |
63 |
>>> Its not really that experimental. We just won't have a livecd release |
64 |
>>> because releng requires a minimal and a universal livecd to do a |
65 |
>>> release, and I only build one thats in between minimal and universal. |
66 |
>>> |
67 |
>>> |
68 |
>> |
69 |
>> |
70 |
>> If you are building a system, you can use any livecd to boot into and |
71 |
>> then download whichever stage tarball and kernel you want. The only |
72 |
>> issue is that your system isn't "hardened" while you are building it. |
73 |
>> Of course if you are really paranoid, then download/verify/burn to a cd |
74 |
>> and use that on the new system before you ever connect to the net. |
75 |
>> |
76 |
>> Dan |
77 |
>> -- |
78 |
>> gentoo-hardened@g.o mailing list |
79 |
>> |
80 |
>> |
81 |
>> |
82 |
> |
83 |
> |
84 |
-- |
85 |
gentoo-hardened@g.o mailing list |