Gentoo Archives: gentoo-hardened

From: Alexander Gabert <pappy@g.o>
To: Chris PeBenito <pebenito@g.o>
Cc: Petre Rodan <petre.rodan@××××××××××××.com>, Felix Leimbach <felix.leimbach@×××.net>, Hardened Gentoo Mail List <gentoo-hardened@g.o>
Subject: Re: [gentoo-hardened] libipt_icmp.so on selinux
Date: Tue, 02 Sep 2003 19:16:08
Message-Id: 1062530180.5913.8.camel@mirage
In Reply to: Re: [gentoo-hardened] libipt_icmp.so on selinux by Chris PeBenito
1 let's try to emerge hardened-gcc and give iptables a recompile using
2 hardened-gcc transparent propolice and etdyn.
3
4 if that does not work and the error persists, i will take a look at it.
5
6 TIA,
7
8 Alex
9
10 On Tue, 2003-09-02 at 20:37, Chris PeBenito wrote:
11 > Someone please post a bug about this, and assign to frogger@g.o.
12 > He's in charge of propolice. We'll have to see if this can be fixed, or
13 > iptables will just have -fstack-protector filtered.
14 >
15 > On Tue, 2003-09-02 at 13:11, Petre Rodan wrote:
16 > > On Tue, Sep 02, 2003 at 06:02:43PM +0200, Felix Leimbach wrote:
17 > > > On Tue, 2 Sep 2003 17:46:55 +0300
18 > > > >
19 > > > > is there someone using selinux-2.4.21-r0 that can confirm if the following command returns 0 on their system:
20 > > > >
21 > > > > iptables -A INPUT -p icmp --icmp-type network-unreachable -j ACCEPT
22 > > >
23 > > > I had the same problem some time ago (used selinux 2.4.20-r? back then),
24 > > > and it turned out, that recompiling iptables without -fstack-protector
25 > > > fixed the problem. For me, the problem was _not_ related to the kernel.
26 > >
27 > > you are right, i was on the wrong track. your solution worked flawlessly.
28 >
29 > --
30 > Chris PeBenito
31 > <pebenito@g.o>
32 > Developer, SELinux
33 > Hardened Gentoo Linux
34 >
35 > Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
36 > Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243
37
38
39
40 --
41 gentoo-hardened@g.o mailing list