Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: Ed Wildgoose <lists@××××××××××.com>
Cc: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Some teething problems with 2004.1 and cascaded profiles
Date: Tue, 27 Apr 2004 22:01:17
Message-Id: 1083103272.25759.62.camel@gorn.pebenito.net
In Reply to: Re: [gentoo-hardened] Some teething problems with 2004.1 and cascaded profiles by Ed Wildgoose
1 On Tue, 2004-04-27 at 16:05, Ed Wildgoose wrote:
2 > Chris PeBenito wrote:
3 > >>Hi I'm having some teething problems with the 2004.1 cascaded profile.
4 > >I need to know what version of portage you are using.
5 >
6 > I'm using 2.0.50-r6 - which should be the latest unmasked build in portage?
7 >
8 > I couldn't bootstrap at all with the cascaded profiles,
9 > bootstrap-cascade.sh would only pickup about 4-5 of the packages, and
10
11 It's come to my attention this afternoon that theres some portage
12 breakage with the stacked profiles. I plan on building the 2004.1
13 stages as soon as this is fixed up.
14
15 > So what I had to do to bootstrap was use the selinux-1.4, and then
16 > switch back to 2004.1 profile before doing the emerge system.
17
18 The best idea would be to do a regular (default) install, and then
19 convert your system with the quickstart guide.
20
21 > OK, I am confusing selinux with hardened, but what I meant to write was
22 > that I want a hardened + selinux machine.
23 [cut]
24 > It's really not clear what needs to be done to get a "hardened" system
25 > right now? For example, do we need any other flags adding to
26 > make.conf...?
27
28 Actually things are in a bit of flux. Hardened-gcc is deprecated, and
29 the replacement (gcc-3.3.3-r[23] with USE=hardened) is still in
30 testing. The term 'hardened' sometimes gets thrown around a little too
31 much. The hardened stages are more precisely pie-ssp stages. You can
32 have SELinux with pie-ssp; it just takes a little work. This is a
33 common request, so I'll probably be making selinux-pie-ssp stages
34 eventually to make this easier.
35
36 --
37 Chris PeBenito
38 <pebenito@g.o>
39 Developer,
40 Hardened Gentoo Linux
41 Embedded Gentoo Linux
42
43 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
44 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] Some teething problems with 2004.1 and cascaded profiles Ed Wildgoose <lists@××××××××××.com>