Gentoo Archives: gentoo-hardened

From: Gordon Malm <gengor@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Grsecurity slows down a web server?
Date: Fri, 23 Jan 2009 19:51:22
Message-Id: 200901231151.16658.gengor@gentoo.org
In Reply to: Re: [gentoo-hardened] Grsecurity slows down a web server? by "Javier J. Martínez Cabezón"
1 No it doesn't.
2
3 On Friday, January 23, 2009 11:18:11 Javier J. Martínez Cabezón wrote:
4 > PaX ignores nx bit in ia32.
5 >
6 > 2009/1/23 Grant <emailgrant@×××××.com>:
7 > >> Try 'pspax'. If there is no NX bit and you enable both PAGEEXEC and
8 > >> SEGMEXEC it should not be using PAGEEXEC.
9 > >
10 > > What should I be looking for from pspax? I have to admit it does seem
11 > > faster now that I've disabled PAGEEXEC.
12 > >
13 > > - Grant
14 > >
15 > >> http://www.bumpin.org/pics/PaX/pax_performance-2.6.24.png
16 > >>
17 > >> Gordon Malm (gengor)
18 > >>
19 > >> On Friday, January 23, 2009 10:14:11 Grant wrote:
20 > >>> > [snip]
21 > >>> >
22 > >>> >> menuconfig isn't letting me disable PAGEEXEC. Maybe it's tied to
23 > >>> >> grsecurity "Gentoo (server)"? I don't want to disable that. Maybe
24 > >>> >> I should live with the slowdown?
25 > >>> >
26 > >>> > No you should not.
27 > >>> >
28 > >>> > After selecting server and saving it. You want to then select
29 > >>> > "Custom" that will leave all the options enabled from "server". You
30 > >>> > then scroll over to the PaX menu and de-select PAGE and select SEGM.
31 > >>> >
32 > >>> > Easy as pie. Good luck.
33 > >>>
34 > >>> Alright, thank you. PAGEEXEC and SEGMEXEC are both selected via
35 > >>> Gentoo (server) so I disabled PAGEEXEC. Should I submit a bug too?
36 > >>>
37 > >>> - Grant