1 |
On 2017-08-19 13:01, Francisco Blas Izquierdo Riera (klondike) wrote: |
2 |
> El 19/08/17 a las 12:37, Aaron W. Swenson escribió: |
3 |
> > On 2017-08-15 17:01, Francisco Blas Izquierdo Riera (klondike) wrote: |
4 |
> >> Hi! |
5 |
> >> |
6 |
> >> I'd like to get this one up by Saturday so that we can proceed with |
7 |
> >> masking and removing of the hardened-sources after upstream stopped |
8 |
> >> releasing new patches. |
9 |
> > I hope I’m not too late. |
10 |
> > |
11 |
> >> We'd like to note that all the userspace hardening and MAC support |
12 |
> >> for SELinux provided by Gentoo Hardened will still remain there and |
13 |
> >> is unaffected by this removal. |
14 |
> > Where is there? I think you’re talking about the packages, but the news |
15 |
> > item is about the kernels. It would help to be more specific here. |
16 |
> > |
17 |
> > That’s all I had that the others hadn’t touched on. |
18 |
> |
19 |
> Do you think something like that is better then? |
20 |
> |
21 |
> We'd like to note that all the userspace hardening and MAC support |
22 |
> for SELinux provided by Gentoo Hardened will still remain available |
23 |
> on the portage. Keep in mind though that the security provided by |
24 |
> these features will be weakened a bit when using |
25 |
> sys-kernel/gentoo-sources. Also, all PaX related packages other than |
26 |
> the hardened-sources will remain available for the time being. |
27 |
> |
28 |
> |
29 |
|
30 |
Much better. We should mention that we’re specifically discussing |
31 |
packages and not portage itself. At least, that’s my understanding from |
32 |
your edit. |
33 |
|
34 |
Here’s my take on it: |
35 |
|
36 |
We'd like to note that all the userspace hardening and MAC support for |
37 |
SELinux provided by Gentoo Hardened will still remain in the packages |
38 |
found in portage. Keep in mind, though, that the security provided by |
39 |
these features will be weakened a bit when using |
40 |
sys-kernel/gentoo-sources. Also, all PaX related packages, except |
41 |
sys-kernel/hardened-sources, will remain available for the time being. |