Gentoo Archives: gentoo-hardened

From: Ned Ludd <solar@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Profile switch: hardened to non-hardened?
Date: Tue, 30 Dec 2008 05:52:21
Message-Id: 1230616337.5528.9.camel@localhost
In Reply to: Re: [gentoo-hardened] Profile switch: hardened to non-hardened? by Grant
1 On Mon, 2008-12-29 at 17:05 -0800, Grant wrote:
2 > >> What else would you recommend for me?
3 > >
4 > > I'd suggest to completely ignore the grsec (low/med/high) options and
5 > > use the Hardened Gentoo level in the hardened-sources all the time.
6 > >
7 > > Xorg should not cause problems unless you are stuck using 3rd party
8 > > binary drivers. Most of us are using a hardened X setup.
9 >
10 > Excellent, thank you. You think the "Hardened Gentoo (workstation)"
11 > and "Hardened Gentoo (server)" grsecurity setups are adequate
12 > low-maintenance solutions?
13
14
15 Re: "low maintenance"
16 I'm not sure we can dumb down the hardening efforts anymore than we
17 already have. It's all pretty transparent and seems mostly like a normal
18 install of anything else. The ELF's are just smarter.
19
20 > What does a hardened profile do for my server?
21
22 Enables things to match the kernel options/blocks things that conflict.

Replies

Subject Author
Re: [gentoo-hardened] Profile switch: hardened to non-hardened? Grant <emailgrant@×××××.com>