Gentoo Archives: gentoo-dev

From: "Tiziano Müller" <dev-zero@g.o>
To: Michael Brinkman <thygreatswaggedone@×××××.com>
Cc: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Hardening a default profile
Date: Thu, 15 Jun 2017 14:39:31
Message-Id: 57fd166c-c67d-0b18-f491-22714cf739ae@gentoo.org
In Reply to: [gentoo-dev] Hardening a default profile by Michael Brinkman
1 Hi Michael
2
3 Am 11.06.2017 um 23:39 schrieb Michael Brinkman:
4 > Hello, so I've been running Gentoo Hardened for a few years on my
5 > laptop, my desktop, and a server made from an older desktop.
6 >
7 > Because of Grsecurity closing access to its source to non-subscribers,
8 > I decided that I would just try to stick with Gentoo-sources and
9 > harden the default profile and follow the KSSP guidelines to get as
10 > close as possible without losing the testing kernel. Because of this,
11 > I no longer used the PaX features and decided switch to the default
12 > profile and enabling my own flags.
13
14 The security people probably have more insight, but I personally run by
15 default the hardened profile, also in combination with gentoo-sources if
16 there were too many compatibility issues with the software I had to run
17 on that specific machine.
18 So, from my point of view there is no reason to switch to the default
19 profile just because the grsec-kernel-patchset isn't open source anymore.
20
21 Best regards,
22 Tiziano