Gentoo Archives: gentoo-dev

From: "Aaron W. Swenson" <titanofold@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] New item for sys-kernel/hardened-sources removal
Date: Sat, 19 Aug 2017 11:18:28
Message-Id: 20170819111820.GC7666@martineau.grandmasfridge.local
In Reply to: Re: [gentoo-dev] New item for sys-kernel/hardened-sources removal by "Francisco Blas Izquierdo Riera (klondike)"
1 On 2017-08-19 13:01, Francisco Blas Izquierdo Riera (klondike) wrote:
2 > El 19/08/17 a las 12:37, Aaron W. Swenson escribió:
3 > > On 2017-08-15 17:01, Francisco Blas Izquierdo Riera (klondike) wrote:
4 > >> Hi!
5 > >>
6 > >> I'd like to get this one up by Saturday so that we can proceed with
7 > >> masking and removing of the hardened-sources after upstream stopped
8 > >> releasing new patches.
9 > > I hope I’m not too late.
10 > >
11 > >> We'd like to note that all the userspace hardening and MAC support
12 > >> for SELinux provided by Gentoo Hardened will still remain there and
13 > >> is unaffected by this removal.
14 > > Where is there? I think you’re talking about the packages, but the news
15 > > item is about the kernels. It would help to be more specific here.
16 > >
17 > > That’s all I had that the others hadn’t touched on.
18 >
19 > Do you think something like that is better then?
20 >
21 > We'd like to note that all the userspace hardening and MAC support
22 > for SELinux provided by Gentoo Hardened will still remain available
23 > on the portage. Keep in mind though that the security provided by
24 > these features will be weakened a bit when using
25 > sys-kernel/gentoo-sources. Also, all PaX related packages other than
26 > the hardened-sources will remain available for the time being.
27 >
28 >
29
30 Much better. We should mention that we’re specifically discussing
31 packages and not portage itself. At least, that’s my understanding from
32 your edit.
33
34 Here’s my take on it:
35
36 We'd like to note that all the userspace hardening and MAC support for
37 SELinux provided by Gentoo Hardened will still remain in the packages
38 found in portage. Keep in mind, though, that the security provided by
39 these features will be weakened a bit when using
40 sys-kernel/gentoo-sources. Also, all PaX related packages, except
41 sys-kernel/hardened-sources, will remain available for the time being.

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] New item for sys-kernel/hardened-sources removal "Francisco Blas Izquierdo Riera (klondike)" <klondike@g.o>
[gentoo-dev] Re: New item for sys-kernel/hardened-sources removal Duncan <1i5t5.duncan@×××.net>