Gentoo Archives: gentoo-hardened

From: dkurtz <dkurtz@××××××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Some questions concerning Hardened-Gentoo
Date: Wed, 06 Jul 2005 16:59:53
Message-Id: 20050706165649.GB3187@ganesha
In Reply to: [gentoo-hardened] Some questions concerning Hardened-Gentoo by Fabian Steiner
1 On Tue, Jul 05, 2005 at 09:52:51PM +0200, Fabian Steiner wrote:
2 > * What's the difference between GrSecurity und SELinux? There are both
3 > in der kernel - so may one use both of them at the same time?
4 >
5 > * Moreover, there are two different portage profiles available -
6 > hardened and selinux. When do I have to use them?
7
8 Go ahead and read thru:
9 http://www.gentoo.org/proj/en/hardened/hardenedfaq.xml
10
11 If you have not already, this can answer your questions better and
12 provides links to the "sub-projects" homepages so you can evaluate
13 what/which options you would like to implement. Most likely you read
14 this and saw that it pointed you here. :)
15
16 Grsec is a series of kernel patches that include PaX and grsec's own role
17 based access control. I choose to use these as they are what brought me
18 to hardended-gentoo in the first place as I manually patched and used
19 them in the past.
20
21 As far as the profiles go, use HARDENED for grsec and then (by
22 exclusion) I can only assume that one would use SELINUX for SELinux. You
23 can intermingle the two "systems" as they are a series of kernel patches
24 and configurations, but you have to choose one access control system, so
25 people seem to tend towards using grsec with pax (hardened) and/or
26 SELinux with RSBAC I believe.
27
28
29 I have not personally used SElinux and RSBAC so others will have to
30 comment on this.
31 http://www.nsa.gov/selinux/info/faq.cfm
32 http://www.rsbac.org/why
33 It seems it's a bit more popular here and looks to have a pretty large
34 community outside of just gentoo. So your support and help options may
35 be greater there, dunno.
36
37
38 --
39 Dave
40 --
41 gentoo-hardened@g.o mailing list