1 |
On Tue, 04 Jul 2006 18:34:25 +0200 |
2 |
pageexec@××××××××.hu wrote: |
3 |
|
4 |
> On 4 Jul 2006 at 16:19, Michael Decker wrote: |
5 |
> > But I've detect that RSBAC and PAX manual are different, could be |
6 |
> > here an error? (showing only the differences here): |
7 |
> > http://www.gentoo.org/proj/en/hardened/rsbac/quickstart.xml |
8 |
> > |
9 |
> > --- SNIP --- |
10 |
> > PaX Control ---> |
11 |
> > [*] Support soft mode (Turn that option off on a production |
12 |
> > kernel) [ ] Use legacy ELF header marking |
13 |
> > [ ] Use ELF program header marking |
14 |
> > Use ELF program header marking MAC system integration (direct) |
15 |
> > ---> (X) direct |
16 |
> |
17 |
> the problem is the MAC integration setting, for RSBAC you need |
18 |
> the 'hook' type (i added it explicitly per Amon's request ;-), |
19 |
> and the gentoo guide is wrong on this. the PaX guide suggests |
20 |
> 'none' because it's, well, a PaX-only guide hence there's no |
21 |
> MAC integration. |
22 |
|
23 |
Documentation fixed :) |
24 |
|
25 |
-- |
26 |
Kevin F. Quinn |