1 |
>> >> >> What else would you recommend for me? |
2 |
>> >> > |
3 |
>> >> > I'd suggest to completely ignore the grsec (low/med/high) options and |
4 |
>> >> > use the Hardened Gentoo level in the hardened-sources all the time. |
5 |
>> >> > |
6 |
>> >> > Xorg should not cause problems unless you are stuck using 3rd party |
7 |
>> >> > binary drivers. Most of us are using a hardened X setup. |
8 |
>> >> |
9 |
>> >> Excellent, thank you. You think the "Hardened Gentoo (workstation)" |
10 |
>> >> and "Hardened Gentoo (server)" grsecurity setups are adequate |
11 |
>> >> low-maintenance solutions? |
12 |
>> > |
13 |
>> > |
14 |
>> > Re: "low maintenance" |
15 |
>> > I'm not sure we can dumb down the hardening efforts anymore than we |
16 |
>> > already have. It's all pretty transparent and seems mostly like a normal |
17 |
>> > install of anything else. The ELF's are just smarter. |
18 |
>> |
19 |
>> Low maintenance definitely. Is the security OK? |
20 |
> |
21 |
> Please think before you type and hit send. |
22 |
> |
23 |
> Pretend you have 0 extra security now. Then you take an entire project |
24 |
> that devotes itself to proactive security measures. It enables features |
25 |
> that are security based. So 0 vs 1... |
26 |
> |
27 |
>> >> What does a hardened profile do for my server? |
28 |
>> > |
29 |
>> > Enables things to match the kernel options/blocks things that conflict. |
30 |
>> |
31 |
>> Is the grsecurity "Hardened Gentoo (workstation)" setting useful |
32 |
>> without the hardened profile? |
33 |
> |
34 |
> Of course it is. Is your make menuconfig (read help) broken? |
35 |
> |
36 |
> We are also getting way off topic here and this thread is going on for a |
37 |
> week. the orig question was answered with a simple "yes". If you have |
38 |
> lots of interactive new questions, jump on irc where you can learn more |
39 |
> in an hour than you can in two months of playing ping/pong on the list. |
40 |
|
41 |
Fair enough, thanks to everyone for their help. |
42 |
|
43 |
- Grant |