1 |
Hi Michael |
2 |
|
3 |
Am 11.06.2017 um 23:39 schrieb Michael Brinkman: |
4 |
> Hello, so I've been running Gentoo Hardened for a few years on my |
5 |
> laptop, my desktop, and a server made from an older desktop. |
6 |
> |
7 |
> Because of Grsecurity closing access to its source to non-subscribers, |
8 |
> I decided that I would just try to stick with Gentoo-sources and |
9 |
> harden the default profile and follow the KSSP guidelines to get as |
10 |
> close as possible without losing the testing kernel. Because of this, |
11 |
> I no longer used the PaX features and decided switch to the default |
12 |
> profile and enabling my own flags. |
13 |
|
14 |
The security people probably have more insight, but I personally run by |
15 |
default the hardened profile, also in combination with gentoo-sources if |
16 |
there were too many compatibility issues with the software I had to run |
17 |
on that specific machine. |
18 |
So, from my point of view there is no reason to switch to the default |
19 |
profile just because the grsec-kernel-patchset isn't open source anymore. |
20 |
|
21 |
Best regards, |
22 |
Tiziano |