Gentoo Logo
Gentoo Spaceship

Installation:
Gentoo Handbook
Installation Docs

Documentation:
Home
Listing
About Gentoo
Philosophy
Social Contract

Resources:
Bug Tracker
Developer List
Discussion Forums
Gentoo BitTorrents
Gentoo Linux Enhancement Proposals
IRC Channels
Mailing Lists
Mirrors
Name and Logo Guidelines
Online Package Database
Security Announcements
Staffing Needs
Supporting Vendors
View our CVS

Graphics:
Logos and themes
Icons
ScreenShots

Miscellaneous Resources:
Gentoo Linux Store
Gentoo-hosted projects
IBM dW/Intel article archive




List Archive: gentoo-hardened
Navigation:
Lists: gentoo-hardened: < Prev By Thread Next > < Prev By Date Next >
Headers:
To: gentoo-hardened@g.o
From: Marco Venutti <veeenrg@...>
Subject: Re: "How hard" is Linux kernel-side hardening?
Date: Sun, 20 Sep 2009 16:16:32 +0200
Hi,<br><br>--[cut]--<br>The jail bug were corrected long ago, and was limited to this module<br>only (in rsbac petitions pass to all modules that are stacked, not<br>only this one, and if only one module deny the request, is denied<br>
forever though jail don&#39;t work properly).<br>--[cut]--<br>
<br>Since I&#39;m a recent Linux user and  I&#39;m not a security cultured, <br>I&#39;ve chosen GR-Security, as starting point, <br>because of its user-friendliness, in fact you can enforce, <br>the bare kernel, also if you are not deeply experienced <br>
in Linux security...<br>this is my case, so I appreciate this opportunity!<br><br>I&#39;ve started from the &quot;Gentoo Hardened Workstation&quot; <br>profile and, then, I&#39;ve done some gradm experiments...<br>these facts in the near past.<br>
<br>I consider myself illiterate, in matter of security,<br>but I&#39;d like to load, a little-little-bit, my lacunas,<br>just for the intellectual pleasure, I feel in satisfy<br>my curiousity.<br><br>I&#39;m not a professional, thus I don&#39;t have <br>
servers to manage, just a couple of workstations, <br>so my needs are, probably, easier to fit...<br>no special high security enforcements are required;<br>this should also be good because gives me<br>the chance to start little, &#39;cause, in effect I&#39;ve<br>
little needs!<br><br>Today is Sunday and I can read some docs,<br>I&#39;m interested in RSBAC and I&#39;m starting to read<br>RSBAC handbook, but at the moment I&#39;m <br>using, yet, GR-Security beacuse of the previous<br>
concept.<br><br>I&#39;ll be glad if there&#39;s anybody willing <br>to indicate me any non-official-but-good how-to<br>and/or any sort of tip useful to get done<br>to &quot;lock-down&quot; my workstation about RSBAC,<br>but I&#39;ll appreciate GR-Sec.&#39;s. <br>
This section is intended to be a request of <br>a little help and does not mean:<br>&quot;Is there anybody does my task, plese?&quot;<br>I&#39;ve specified the sense of the statement,<br>just to clear every possible ambiguity.<br>
<br><br>I wish you a good sunday afternoon ;-)<br>
Replies:
Re: "How hard" is Linux kernel-side hardening?
-- Javier J . Martínez Cabezón
References:
"How hard" is Linux kernel-side hardening?
-- Marco Venutti
Re: "How hard" is Linux kernel-side hardening?
-- Javier J . Martínez Cabezón
Navigation:
Lists: gentoo-hardened: < Prev By Thread Next > < Prev By Date Next >
Previous by thread:
Re: "How hard" is Linux kernel-side hardening?
Next by thread:
Re: "How hard" is Linux kernel-side hardening?
Previous by date:
Re: "How hard" is Linux kernel-side hardening?
Next by date:
Re: "How hard" is Linux kernel-side hardening?


Updated Nov 22, 2009

Donate to support our development efforts.

Gentoo Centric Hosting: vr.org

VR Hosted

Tek Alchemy

Tek Alchemy

SevenL.net

SevenL.net

php|architect

php|architect

Copyright 2001-2007 Gentoo Foundation, Inc. Questions, Comments? Email www@gentoo.org.