Subject: Re: [gentoo-hardened] Re: [gentoo-security] Re: Mini Gentoo in VMWare
Date: Fri, 03 Nov 2006 17:47:55
Running a chroot jailed service in a chroot jailed xD

It's kind of redundant but I don't know if it's worthy.

On 11/3/06, Antoine Martin <antoine@××××××××××.uk> wrote:
> Would a server in a VM actually be more secure than a server in a
> "hardened" chroot jail?
IMO yes, but since you can have both...

> (though I'd guess that a hardened system would be the best basis for a
> server, VM or chroot; and the logical placement of a VM would be within
> a chroot jail?).
A properly configured VM running in a hardened chroot is going to be
(almost) impossible to escape.

Note you can also contain your VMs with SELinux (both inside and out).
I've posted some pages on how to do this with UML here:
http://www.sxpert.org/selinux/uml/

Antoine