1 |
I've been using OpenBSD for a while now which has priv dropping X and |
2 |
the machdep.allowaperture=[0|1|2]. Theo has said firefox also |
3 |
annoyingly uses it's own memory management. |
4 |
|
5 |
I have a few questions about Grsec that I'd love some input on as I am |
6 |
struggling to find the answers to them at the moment. |
7 |
|
8 |
I've read on the Gentoo-hardened archive and grsec config help that the |
9 |
iopl and ioperm should be protected with rbac if priviledged I/O is |
10 |
allowed. |
11 |
|
12 |
So you can disable the RAW_IO capability to all and sacrifice xrestarts. |
13 |
But if X already has all priviledges then I guess your just adding a |
14 |
hurdle which is made a bit higher with grsec, so obfuscation really |
15 |
and not complete security. Is there anything else you can do or is that |
16 |
what is meant by "You should use RBAC if you allow priviledged I/O"? |
17 |
|
18 |
The gentoo-handbook says something like the question of selinux|rbac| |
19 |
rsbac is a controversial one. It seems rsbac is the most secure but |
20 |
more difficult to use and has less starter policies around. Gentoo |
21 |
seems to have selinux policies. Does selinux have any more to offer than |
22 |
rbac for protecting X? |
23 |
|
24 |
Does CONFIG_PAX_MPROTECT_COMPAT have any effect on firefox and did |
25 |
mozilla refuse to patch their sources with the if !jit patch? |
26 |
|
27 |
Thanks |
28 |
|
29 |
Kc |