Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: Petre Rodan <petre.rodan@××××××××××××.com>
Cc: Felix Leimbach <felix.leimbach@×××.net>, Hardened Gentoo Mail List <gentoo-hardened@g.o>
Subject: Re: [gentoo-hardened] libipt_icmp.so on selinux
Date: Tue, 02 Sep 2003 18:37:57
Message-Id: 1062527873.8467.3.camel@chris.pebenito.net
In Reply to: Re: [gentoo-hardened] libipt_icmp.so on selinux by Petre Rodan
1 Someone please post a bug about this, and assign to frogger@g.o.
2 He's in charge of propolice. We'll have to see if this can be fixed, or
3 iptables will just have -fstack-protector filtered.
4
5 On Tue, 2003-09-02 at 13:11, Petre Rodan wrote:
6 > On Tue, Sep 02, 2003 at 06:02:43PM +0200, Felix Leimbach wrote:
7 > > On Tue, 2 Sep 2003 17:46:55 +0300
8 > > >
9 > > > is there someone using selinux-2.4.21-r0 that can confirm if the following command returns 0 on their system:
10 > > >
11 > > > iptables -A INPUT -p icmp --icmp-type network-unreachable -j ACCEPT
12 > >
13 > > I had the same problem some time ago (used selinux 2.4.20-r? back then),
14 > > and it turned out, that recompiling iptables without -fstack-protector
15 > > fixed the problem. For me, the problem was _not_ related to the kernel.
16 >
17 > you are right, i was on the wrong track. your solution worked flawlessly.
18
19 --
20 Chris PeBenito
21 <pebenito@g.o>
22 Developer, SELinux
23 Hardened Gentoo Linux
24
25 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
26 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] libipt_icmp.so on selinux Alexander Gabert <pappy@g.o>