Gentoo Archives: gentoo-hardened

From: Hinnerk van Bruinehsen <h.v.bruinehsen@×××××××××.de>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Re: Required Priorities (Security) = slow server
Date: Fri, 17 Aug 2012 09:03:30
Message-Id: 502DFD5F.9030001@fu-berlin.de
In Reply to: [gentoo-hardened] Re: Required Priorities (Security) = slow server by Grant
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 On 17.08.2012 08:56, Grant wrote:
5 >> I recently moved my server from:
6 >>
7 >> 3.2.11-hardened Security Level (Hardened Gentoo [server])
8 >>
9 >> to:
10 >>
11 >> 3.4.5-hardened Configuration Method (Automatic) Usage Type
12 >> (Server) Virtualization Type (None) Required Priorities
13 >> (Security)
14 >>
15 >> and http became extremely slow. Some pages that would normally
16 >> execute in 1 second would take 10 seconds or more. There is a
17 >> lot of php and perl server-side stuff so the slowdown may have
18 >> been rooted in that. I changed to Required Priorities
19 >> (Performance) and everything sped back up to normal. My laptop
20 >> was moved to the following at the same time and I didn't notice
21 >> any performance change:
22 >>
23 >> 3.4.5-hardened Configuration Method (Automatic) Usage Type
24 >> (Desktop) Virtualization Type (None) Required Priorities
25 >> (Security)
26 >>
27 >> Is this sort of behavior expected from a server?
28 >>
29 >> - Grant
30 >
31 > This may have been a false alarm. I think I've been having
32 > intermittent network problems to part of the internet. Can anyone
33 > confirm that the above config shouldn't slow down an http server?
34 >
35 > - Grant
36 >
37
38 It's hard to make any generalisations but I have some servers with
39 similar grsec-autoconfig (server instead of desktop) and no noticable
40 slowdown (I'd say nothing more that 10%).
41 I'd recommend to use 3.5.1-r2 (testing) or 3.2.27 (stable), though.
42
43 WKR
44 Hinnerk
45 -----BEGIN PGP SIGNATURE-----
46 Version: GnuPG v2.0.19 (GNU/Linux)
47 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
48
49 iQEcBAEBAgAGBQJQLf1fAAoJEJwwOFaNFkYcZ98IAJ1RUmreIf0HW7AqyNl9LjUA
50 5sHkDKnepkmdwdUBA61VBJXjicfreBi+I3g9GmIrm6SY2pYseNogi92YYqRHNi9c
51 cxHHr7z2M/fLjApFE9JqAZpKcSBzr4fwUECS7qzFz16XXrNxOFnmdbBY9ewxdHxB
52 QeQnWBNaem/1qrzdifOE9nCZgkhDaZ2X+1EgYcGA3yPh6fNwNDL/mfkVCyU2jhra
53 zZbB5v9QzSrWe4Her8KPPTnaUrtQsukLZGI3g4IulrBLxkuqsh8StCA0A4cyokJ4
54 Vl+AjykYEvtxzWE1mVy4bCNSWlLCmmLOVlZ3hEWRQ701CL2lXgYTS/PWHJ9mjwI=
55 =YPvF
56 -----END PGP SIGNATURE-----

Replies

Subject Author
Re: [gentoo-hardened] Re: Required Priorities (Security) = slow server Grant <emailgrant@×××××.com>