Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] hardened profile for desktops?
Date: Sat, 09 Jun 2012 00:02:49
Message-Id: 35a2407a38960b8807cb3e71c91c6a5c.squirrel@atoth.sote.hu
In Reply to: Re: [gentoo-hardened] hardened profile for desktops? by Kevin Chadwick
1 I for one used Trusted Debian / Adamantix before Hardened Gentoo.
2 It was a distro of choice based on Debian and promoted SSP and PaX-enabled
3 kernels.
4 The main problem was, that it practically remained a one man project, led
5 by Peter Busser. After some time - probably due to the lack of enough
6 resources - it became slowly out of date. Until it was officially
7 admitted, that it wasn't recommended to install it on a server.
8
9 Long before this I had already switched to Hardened Gentoo. I would say,
10 that although there are some other security related Linux projets,
11 Hardened Gentoo is definitely alive. I don't know what is the current
12 situation regarding Owl Linux, or for example LIDS. And there were also
13 some other distros like Immunix and Trustix...
14
15 I think Hardened Gentoo install is not substantially more complicated to
16 install compared to a regular Gentoo install nowdays. It would be the
17 recommended first distro for a newbie. If there would be some popular
18 commodity Gentoo-based distros, it would be hard to convert them to
19 hardened. There's for example Ututo. But it's not popular enough.
20
21 What I'm currently missing as a Grsecurity user is a lack of reference
22 policy out-of-the box. SELinux is the best from this point of view. But
23 it's not easy to accomodate a user specific change. Moreover, a regular
24 user wouldn't want to tweak around to craft his own RBAC policy.
25
26 I wish Hardened Gentoo will live long. Gentoo turned out to be a viable
27 base for a hardened solution - instead of a binary distro. Thanks for all
28 effort of the developers.
29
30 Dw.
31 --
32 dr Tóth Attila, Radiológus, 06-20-825-8057
33 Attila Toth MD, Radiologist, +36-20-825-8057
34
35 2012.Június 8.(P) 21:40 időpontban Kevin Chadwick ezt írta:
36 > On Fri, 8 Jun 2012 16:06:37 +0300
37 > Alex Efros wrote:
38 >
39 >> Actually, I see no reasons to NOT use hardened on desktops.
40 >
41 > Maybe many more would if there was an easy and quick to install and
42 > maintain compiled distro. More users more compatibility too, I'd guess.
43 >
44 > Not suggesting there should be, just stating a reality.
45 >
46 > Anyone know why hardened debian and was it adamantix died off?
47 >

Replies

Subject Author
Re: [gentoo-hardened] hardened profile for desktops? "Tóth Attila" <atoth@××××××××××.hu>