Gentoo Archives: gentoo-dev

From: Joachim Blaabjerg <styx@×××××.org>
To: gentoo-dev@g.o
Subject: Re: [gentoo-dev] Secure Gentoo - What do you think?
Date: Tue, 08 Jan 2002 12:17:27
Message-Id: 20020108191815.75220efd.styx@SuxOS.org
In Reply to: Re: [gentoo-dev] Secure Gentoo - What do you think? by Grant Goodyear
1 On 08 Jan 2002 10:27:15 -0500
2 Grant Goodyear <goodyea@×××××××.edu> wrote:
3 >
4 > Gads, I hope not! If you do need to modify all of the ebuilds, then we
5 > haven't done our jobs very well.
6
7 There are a few problems that hopefully can be avoided easily, such as post
8 installation routines. I was planning on using a modularized script to update
9 the LIDS ACLs, and letting every new program add ACLs for itself in one
10 directory (one file for each program) upon installation. The problem (if one can
11 call it that) is that I've recently decided to make a deny-all type of LIDS
12 configuration, so every program that intends to do anything in particular will
13 need specialized LIDS ACLs... So unless there is a special way of doing this, I
14 think I'll have to modify a couple of .ebuild files... :-/ Luckily, I don't
15 intend to include all the programs you guys have made .ebuild files for, such as
16 X, Gnome, KDE, and other applications that are strictly unneccessary (and maybe
17 even a security risk) on a dedicated server.
18
19 > As for where to start, I assume you've installed Gentoo once or twice to get a
20 > good feel for how it works?
21
22 Hopefully, I'll get an ADSL connection tomorrow (after waiting for a couple of
23 years...), so I can install Gentoo for the first time. I downloaded the .iso,
24 but downloading tens or hundreds of megabytes of source isn't really feasible
25 when you're connected to the 'net with a 56k modem ;)
26
27 > Then I would start on building a minimal SuxOS system. You'll
28 > presumably need to modify the bootstrap.sh script to compile glibc
29 > with formatguard, create a SuxOS kernel ebuild that includes all of the
30 > necessary patches, and make a /usr/portage/profiles/SuxOS/packages file
31 > tailored to SuxOS needs. Come play on #gentoo on irc.openprojects.net;
32 > we'll be happy to help!
33
34 #gentoo, here I come! ;)
35
36 BTW, have you guys got any ideas for a name?
37
38 Regards
39
40 --
41 Joachim Blaabjerg
42 styx@×××××.org
43 www.SuxOS.org

Replies

Subject Author
Re: [gentoo-dev] Secure Gentoo - What do you think? "Tod M. Neidt" <tneidt@××××××.com>