Gentoo Archives: gentoo-hardened

From: Grant <emailgrant@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Profile switch: hardened to non-hardened?
Date: Thu, 01 Jan 2009 16:22:48
Message-Id: 49bf44f10901010822h19ee27a4reb482bb9ddd8d329@mail.gmail.com
In Reply to: Re: [gentoo-hardened] Profile switch: hardened to non-hardened? by Ned Ludd
1 >> >> >> What else would you recommend for me?
2 >> >> >
3 >> >> > I'd suggest to completely ignore the grsec (low/med/high) options and
4 >> >> > use the Hardened Gentoo level in the hardened-sources all the time.
5 >> >> >
6 >> >> > Xorg should not cause problems unless you are stuck using 3rd party
7 >> >> > binary drivers. Most of us are using a hardened X setup.
8 >> >>
9 >> >> Excellent, thank you. You think the "Hardened Gentoo (workstation)"
10 >> >> and "Hardened Gentoo (server)" grsecurity setups are adequate
11 >> >> low-maintenance solutions?
12 >> >
13 >> >
14 >> > Re: "low maintenance"
15 >> > I'm not sure we can dumb down the hardening efforts anymore than we
16 >> > already have. It's all pretty transparent and seems mostly like a normal
17 >> > install of anything else. The ELF's are just smarter.
18 >>
19 >> Low maintenance definitely. Is the security OK?
20 >
21 > Please think before you type and hit send.
22 >
23 > Pretend you have 0 extra security now. Then you take an entire project
24 > that devotes itself to proactive security measures. It enables features
25 > that are security based. So 0 vs 1...
26 >
27 >> >> What does a hardened profile do for my server?
28 >> >
29 >> > Enables things to match the kernel options/blocks things that conflict.
30 >>
31 >> Is the grsecurity "Hardened Gentoo (workstation)" setting useful
32 >> without the hardened profile?
33 >
34 > Of course it is. Is your make menuconfig (read help) broken?
35 >
36 > We are also getting way off topic here and this thread is going on for a
37 > week. the orig question was answered with a simple "yes". If you have
38 > lots of interactive new questions, jump on irc where you can learn more
39 > in an hour than you can in two months of playing ping/pong on the list.
40
41 Fair enough, thanks to everyone for their help.
42
43 - Grant