Gentoo Archives: gentoo-hardened

From: Clemente Aguiar <ca-lists@××××××××××××××××.pt>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Which profile?
Date: Wed, 11 Feb 2009 09:37:27
Message-Id: 1234345043.28777.34.camel@caguiar-linux.madeiratecnopolo.pt
In Reply to: Re: [gentoo-hardened] Which profile? by Ned Ludd
1 Ter, 2009-02-10 às 10:40 -0800, Ned Ludd escreveu:
2 > On Tue, 2009-02-10 at 19:17 +0100, Thomas Sachau wrote:
3 > > Cyprien Nicolas schrieb:
4 > > > 2009/2/10 Matthew Summers <msummers42@×××××.com>:
5 > > >> On Tue, Feb 10, 2009 at 4:04 AM, Tom Hendrikx <tom@×××××××××.net> wrote:
6 > > >>> Clemente Aguiar schreef:
7 > > >>>> I understand that the profiles where updated recently (last year?).
8 > > >>>>
9 > > >>>> Available profile symlink targets:
10 > > >>>> [1] hardened/amd64 *
11 > > >>>> [2] hardened/amd64/multilib
12 > > >>>> [3] selinux/2007.0/amd64
13 > > >>>> [4] selinux/2007.0/amd64/hardened
14 > > >>>> [5] default/linux/amd64/2008.0
15 > > >>>> [6] default/linux/amd64/2008.0/desktop
16 > > >>>> [7] default/linux/amd64/2008.0/developer
17 > > >>>> [8] default/linux/amd64/2008.0/no-multilib
18 > > >>>> [9] default/linux/amd64/2008.0/server
19 > > >>>> [10] hardened/linux/amd64
20 > > >>>>
21 > > >>>> Available profile symlink targets:
22 > > >>>> [1] hardened/x86/2.6 *
23 > > >>>> [2] selinux/2007.0/x86
24 > > >>>> [3] selinux/2007.0/x86/hardened
25 > > >>>> [4] default/linux/x86/2008.0
26 > > >>>> [5] default/linux/x86/2008.0/desktop
27 > > >>>> [6] default/linux/x86/2008.0/developer
28 > > >>>> [7] default/linux/x86/2008.0/server
29 > > >>>> [8] hardened/linux/x86
30 > > >>>>
31 > > >>>>
32 > > >>>> I would like to know what hardened profile I should use when I build new
33 > > >>>> machines? (AMD64 as well as x86)
34 > > >>>>
35 > > >>>> Thanks.
36 > > >>>>
37 > > >>>>
38 > > >>>>
39 > > >>> A few days ago I switched an x86 machine from "default/linux/x86/2008.0"
40 > > >>> to "hardened/linux/x86/2008.0/server" after some arbitrary rummaging in
41 > > >>> the profiles directory. This gave me no problems other than the expected
42 > > >>> gcc-4 -> gcc-3 downgrade.
43 > > >>>
44 > > >>> I'm not sure why this profile isn't listed in the eselect profile
45 > > >>> listing above. It doesn't give me a big fat "unsupported profile"
46 > > >>> warning though...
47 > > >>>
48 > > >>> Regards,
49 > > >>> Tom
50 > > >>>
51 > > >>
52 > > >> This is a confusing situation. I am currently using
53 > > >> /usr/portage/profiles/hardened/linux/amd64/2008.0.
54 > > >>
55 > > >> This is not explicitly listed in the output of 'eselect profile list'.
56 > > >>
57 > > >> Perhaps we could sort this out on the list & then I will write a quick doc
58 > > >> to place in the hardened web space to assist other users.
59 > > >>
60 > > >> --
61 > > >> M. Summers
62 > > >>
63 > > >> "...there are no rules here -- we're trying to accomplish something."
64 > > >> - Thomas A. Edison
65 > > >>
66 > > >
67 > > > On #gentooo-hardened, I got this answer :
68 > > >
69 > > > Feb 04 20:10:51 <Tommy[D]> Anyone can say, which profile of the 2
70 > > > hardened ones are supported here?
71 > > > Feb 04 20:12:01 <gengor> Tommy[D]: use hardened/${ARCH}/2.6
72 > > >
73 > > > But it was not listed by Clemente for amd64
74 > > >
75 > > > --
76 > > > Cyprien
77 > > >
78 > > >
79 > >
80 > > So he should use either /hardened/amd64 or /hardened/amd64/multilib. If i rememember it right, the
81 > > other profile (/hardened/linux/* ) is not under control by the hardened team and because of that not
82 > > supported.
83 >
84 > Correct.
85 >
86 > amd64 #1 or #2 (suggested #2)
87 > x86 #1
88 >
89
90 This is what I wanted to know. Thanks.

Replies

Subject Author
Re: [gentoo-hardened] Which profile? Tom Hendrikx <tom@×××××××××.net>