Gentoo Archives: gentoo-hardened

From: Grant <emailgrant@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Grsecurity slows down a web server?
Date: Fri, 23 Jan 2009 17:51:51
Message-Id: 49bf44f10901230951g2d687d87md8f7c629a72423d4@mail.gmail.com
In Reply to: Re: [gentoo-hardened] Grsecurity slows down a web server? by Ned Ludd
1 >> >> >> My website seems a bit slower since I enabled grsecurity on that
2 >> >> >> system. Is that typical? Is it most likely due to MPROTECT, or
3 >> >> >> something else?
4 >> >> >
5 >> >> > can you quantify this slowdown? and what grsec/pax features did you enable?
6 >> >>
7 >> >> I enabled the grsecurity "Gentoo (server)" profile in the hardened
8 >> >> kernel.
9 >> >
10 >> > ok, is PAGEEXEC enabled (and SEGMEXEC isn't) and is your cpu some P4 variant
11 >> > without NX support? that's about the only situation where you should see an
12 >> > observable slowdown, otherwise i doubt you can percieve a few % without
13 >> > actual measurements. so if neither is your case, it's definitely worth an
14 >> > investigation.
15 >>
16 >> Very close. PAGEEXEC is enabled, but so is SEGMEXEC. My CPU is a
17 >> P4-2.8, and I'm not sure about NX support but these are the flags:
18 >
19 >
20 > Disable PAGEEXEC and switch to SEGMEXEC on the P4. That slowdown will go
21 > away. No idea why on earth the (server) options would enable such a
22 > thing on the x86 platform.
23
24 menuconfig isn't letting me disable PAGEEXEC. Maybe it's tied to
25 grsecurity "Gentoo (server)"? I don't want to disable that. Maybe I
26 should live with the slowdown?
27
28 - Grant

Replies

Subject Author
Re: [gentoo-hardened] Grsecurity slows down a web server? Ned Ludd <solar@g.o>