Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] global_ssp boolean
Date: Tue, 26 Jun 2007 16:44:14
Message-Id: 1182876092.5131.20.camel@defiant.pebenito.net
In Reply to: [gentoo-hardened] global_ssp boolean by Bill Sharer
1 On Sun, 2007-06-24 at 20:41 -0400, Bill Sharer wrote:
2 > Chris P and company
3 >
4 > While rummaging through my dmesg's I found a lot of denials related to
5 > the urandom device and then found the global_ssp boolean when looking at
6 > stuff through apol. (20070329 ref policy btw). Anyway I also saw this
7 >
8 > http://www.nsa.gov/selinux/list-archive/0603/thread_body35.cfm
9 >
10 > documenting this gentoo-only flag. The only trouble is that the
11 > booleans.conf that unpacks with the reference policy has this set to
12 > false. Is this worth a trip to bugzilla to write it up?
13
14 setsebool -P global_ssp 1
15
16 That will enable it and make it so it is set on boot. The purpose of
17 booleans is to provide options to the users.
18
19 --
20 Chris PeBenito
21 <pebenito@g.o>
22 Developer,
23 Hardened Gentoo Linux
24
25 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
26 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature