Gentoo Archives: gentoo-hardened

From: Robert Welz <welz@×××××××××.de>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Gentoo Hardened + Xen + Pax + Grsecurity
Date: Fri, 16 Mar 2007 15:35:42
Message-Id: 0AB3A74A-EEDB-4EF1-A76A-A89E44102FE6@fixe-post.de
In Reply to: [gentoo-hardened] Gentoo Hardened + Xen + Pax + Grsecurity by Andreas Philipp
1 Am 16.03.2007 um 14:58 schrieb Andreas Philipp:
2
3 > Hi Guys,
4 >
5 > I'm new to Gentoo Hardened. So please be patient if I'm asking
6 > stupid questions. On my server running xen-3.0.2 I'm trying to set
7 > up a domU runnig Gentoo Hardened with Pax and Grsecurity. Now i've
8 > three question:
9 > 1) Is this possible/meanigfull?
10
11 I am not shure if there are patches for Pax/grsec for xen, all I
12 found on the net was older experimental stuff.
13
14 > 2) I'm using a stage3 from the 2006.1 profile and then I must
15 > DOWNGRADE glibc (I got it work...). Is this normal/o.k.?
16
17 Don't DOWNGRADE glibc!
18
19 Well, if you suceed, fine.
20 I tried 3 days on a real PC and was about to despair. Later found out
21 that hardened stage-3 (2006.0) archives exists on the gentoo servers.
22 Somewhere under experimental/ .
23
24
25 > 3) Does anyone know a good guide to get familiar with those
26 > security enhancements?
27
28 The readings on the gentoo webside will give you a quick and
29 sufficient start along with links to the projects itsef.
30
31 > My architecture: Intel Core 2 Duo, so I've a x86-64/amd64 with smp.
32 > At the moment all system are 64bit and would like to keep that if
33 > possilbe.
34
35 >
36 > Thanks,
37 > Andreas
38 > --
39 > gentoo-hardened@g.o mailing list
40 >
41 >
42
43 j m 2 ct's,
44 Robert
45
46
47
48
49 --
50 gentoo-hardened@g.o mailing list