Gentoo Archives: gentoo-hardened

From: Chris Smart <taskara@××××××××××××.net>
To: gentoo-hardened@××××××××××××.org
Subject: Re: [gentoo-hardened] SElinux
Date: Mon, 04 Apr 2005 23:10:49
Message-Id: 4251C977.2040907@internode.on.net
In Reply to: Re: [gentoo-hardened] SElinux by Genco YILMAZ
1 Hi Genco,
2
3 I have just been discussing an AMD64 hardened build on this ML, and what
4 I was advised to do was to build the system with the standard profile
5 (../profiles/default-linux/amd64/2005.0/no-multilib/) and the hardened
6 use flag.
7
8 Then, once the system is up and running to use this guide to convert
9 your system to selinux:
10
11 http://www.gentoo.org/proj/en/hardened/selinux/selinux-amd64-handbook.xml?part=2&chap=0
12
13 If you are using x86 system, then you should be able to use a standard
14 livecd with the selinux-stage3 tarball, and follow this guide:
15
16 http://www.gentoo.org/proj/en/hardened/selinux/selinux-x86-handbook.xml
17
18 or you could install a standard system with stage3 and convert it
19
20 http://www.gentoo.org/proj/en/hardened/selinux/selinux-x86-handbook.xml?part=2&chap=0
21
22 Hope this helps, and please forgive me if I'm off the mark somewhere!
23
24 Cheers,
25 Chris
26
27 Genco YILMAZ wrote:
28
29 > Many thanks ,
30 > I it more clear than before now.
31 >
32 > regards.
33 >
34 >
35 > Dan Gregory wrote:
36 >
37 >> Chris PeBenito wrote:
38 >>
39 >>
40 >>> On Mon, 2005-04-04 at 17:17 +0300, Matan Peled wrote:
41 >>>
42 >>>
43 >>>
44 >>>> Genco YILMAZ wrote:
45 >>>>
46 >>>>
47 >>>>
48 >>>>> hi,
49 >>>>> I would like to install a new SElinux gentoo for a production server
50 >>>>> but I am a littled bit confused.
51 >>>>> SELinux livecd is located under experimental directory in gentoo
52 >>>>> mirrors. Is it safe to use
53 >>>>> SELinux gentoo for a production server when it is properly
54 >>>>> configured?
55 >>>>>
56 >>>>> thanks.
57 >>>>>
58 >>>>
59 >>>> The LiveCD is expermintal, but Gentoo's SELinux support is pretty
60 >>>> stable.
61 >>>>
62 >>>
63 >>> Its not really that experimental. We just won't have a livecd release
64 >>> because releng requires a minimal and a universal livecd to do a
65 >>> release, and I only build one thats in between minimal and universal.
66 >>>
67 >>>
68 >>
69 >>
70 >> If you are building a system, you can use any livecd to boot into and
71 >> then download whichever stage tarball and kernel you want. The only
72 >> issue is that your system isn't "hardened" while you are building it.
73 >> Of course if you are really paranoid, then download/verify/burn to a cd
74 >> and use that on the new system before you ever connect to the net.
75 >>
76 >> Dan
77 >> --
78 >> gentoo-hardened@g.o mailing list
79 >>
80 >>
81 >>
82 >
83 >
84 --
85 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] SElinux Genco YILMAZ <gyilmaz@×××××××××.tc>
Re: [gentoo-hardened] SElinux Jason K Larson <gentoo-hardened@××××××××××.org>