Gentoo Archives: gentoo-hardened

From: Kevin Chadwick <ma1l1ists@××××××××.uk>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Grsec X11 Rbac Selinux Priviledged/Raw I/O Mprotect Firefox
Date: Sun, 06 Nov 2011 23:19:33
Message-Id: 20111106231918.33254318.ma1l1ists@yahoo.co.uk
1 I've been using OpenBSD for a while now which has priv dropping X and
2 the machdep.allowaperture=[0|1|2]. Theo has said firefox also
3 annoyingly uses it's own memory management.
4
5 I have a few questions about Grsec that I'd love some input on as I am
6 struggling to find the answers to them at the moment.
7
8 I've read on the Gentoo-hardened archive and grsec config help that the
9 iopl and ioperm should be protected with rbac if priviledged I/O is
10 allowed.
11
12 So you can disable the RAW_IO capability to all and sacrifice xrestarts.
13 But if X already has all priviledges then I guess your just adding a
14 hurdle which is made a bit higher with grsec, so obfuscation really
15 and not complete security. Is there anything else you can do or is that
16 what is meant by "You should use RBAC if you allow priviledged I/O"?
17
18 The gentoo-handbook says something like the question of selinux|rbac|
19 rsbac is a controversial one. It seems rsbac is the most secure but
20 more difficult to use and has less starter policies around. Gentoo
21 seems to have selinux policies. Does selinux have any more to offer than
22 rbac for protecting X?
23
24 Does CONFIG_PAX_MPROTECT_COMPAT have any effect on firefox and did
25 mozilla refuse to patch their sources with the if !jit patch?
26
27 Thanks
28
29 Kc

Replies

Subject Author
Re: [gentoo-hardened] Grsec X11 Rbac Selinux Priviledged/Raw I/O Mprotect Firefox "Anthony G. Basile" <blueness@g.o>
Re: [gentoo-hardened] Grsec X11 Rbac Selinux Priviledged/Raw I/O Mprotect Firefox "Javier Juan Martínez Cabezón" <tazok.id0@×××××.com>