Gentoo Archives: gentoo-hardened

From: R0b0t1 <r030t1@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Hardening a Kernel post hardened-sources
Date: Wed, 28 Mar 2018 18:22:56
Message-Id: CAAD4mYhNDvP+NRJ+xrygzYWkRw4wZ3UhmBPyhPhbL6z1Z8M1CQ@mail.gmail.com
In Reply to: Re: [gentoo-hardened] Hardening a Kernel post hardened-sources by Alex Efros
1 On Wed, Mar 28, 2018 at 12:40 PM, Alex Efros <powerman@××××××××.name> wrote:
2 > Hi!
3 >
4 > On Wed, Mar 28, 2018 at 06:06:00PM +0100, Robert Sharp wrote:
5 >> Does anyone know of a good, post GRSecurity guide to reasonable security
6 >> for the kernel? In the absence of anything else I will have to go back
7 >> to the KSPP list and start removing stuff until I can get a stable kernel.
8 >
9 > I'm using https://github.com/minipli/linux-unofficial_grsec, but it lacks
10 > Spectre and Meltdown mitigation at the moment (see issues). Still, I
11 > believe it's the best we can have now (better is probably paid GrSec, but
12 > AFAIK it's impossible or too costly to buy it for home or small business).
13 >
14
15 Previous contributors have access to the code, but it doesn't seem
16 like there is any way to go that route anymore.

Replies

Subject Author
Re: [gentoo-hardened] Hardening a Kernel post hardened-sources Guillaume Ceccarelli <guillaume@××××××××××××.com>