Gentoo Archives: gentoo-hardened

From: Ed W <lists@××××××××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Towards better profiles for hardened.
Date: Mon, 18 Jan 2010 18:00:47
Message-Id: 4B5489BC.2090304@wildgooses.com
In Reply to: Re: [gentoo-hardened] Towards better profiles for hardened. by Shinkan
1 On 14/01/2010 12:16, Shinkan wrote:
2 >
3 >
4 > 2010/1/13 basile <basile@××××××××××××××.edu
5 > <mailto:basile@××××××××××××××.edu>>
6 >
7 > Hi guys,
8 >
9 > I'm emailing because the profile issue came up again in IRC. I'd like
10 > to continue the discussion here. Let me try to get it started.
11 >
12 > Here's some general issues with the current profile stucture:
13 >
14 > 1) It is horribly complex and difficult to read the inheritance
15 > strucutre. Its not clear the inheritance even works. As a
16 > result, the
17 > user is not sure what is going on. This ambiguity makes it difficult
18 > to even start a coherent criticism!
19 >
20 > 2) There doesn't appear to be a good structure for seperation of
21 > various
22 > features. In OO language, I can't choose what to inherit. I wind up
23 > getting stuff from other profiles which I don't want and can't control
24 > this, so I'm tempted to just USE="-*" and start from scratch, which is
25 > not a good thing.
26 >
27 > 3) There is a clear bias towards the desktop. If you go that
28 > route, you
29 > get what you need/want. When you deviate, you start to get more
30 > things
31 > that you don't want/need and have to struggle against points 1 and 2.
32 >
33 > This effects hardened and hardened+server most. Comments?
34 >
35 >
36 > I don't really get the productive side of this message, but I do agree
37 > with all that points.
38 >
39
40 I think to some extent this may need to get pushed further up to whoever
41 manages the main gentoo profiles? The problem seems a bit deeper
42 routed, but things seem to be either getting worse or better depending
43 on whether you like the current direction of progress?
44
45 A follow on point is that getting some public docs/howtos on building
46 your own profiles would be really useful. I figured out the major
47 details and use it here on a bunch of linux-vservers and it's absolutely
48 fantastic for getting all servers largely the same and baselining the
49 software install. However, it wasn't that intuitive to start with
50
51 Anyway, sounds good - what do we do next?
52
53 Ed