Gentoo Archives: gentoo-hardened

From: Guillaume Ceccarelli <guillaume@××××××××××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Hardening a Kernel post hardened-sources
Date: Thu, 29 Mar 2018 10:48:03
Message-Id: 467F3E15-D7B4-411F-994B-780871AA83A4@gcs-ventures.com
In Reply to: Re: [gentoo-hardened] Hardening a Kernel post hardened-sources by R0b0t1
1 Hi all,
2
3 I’ve been a grsecurity customer for a little over two years now, and my use of it is as a small business, on Gentoo server installations. While I can’t disclose the amount of money I’m paying publicly because every deal is customized, I would encourage you to get in touch using the contact form on grsecurity.net and ask for a quote if you haven’t already.
4
5 You might just end up with an arrangement you can afford, and grsec is still certainly worth having today. Not only for the feature set, but also for the constant looking over the mainline Linux kernel code, including fixing and backporting more fixes than the regular kernel stable releases, and for knowledge / emails giving context to important kernel vulnerabilities when they occur.
6
7
8 Best,
9
10 – Guillaume Ceccarelli
11
12 >> On 28 Mar 2018, at 20:22, R0b0t1 <r030t1@×××××.com> wrote:
13 >>
14 >> On Wed, Mar 28, 2018 at 12:40 PM, Alex Efros <powerman@××××××××.name> wrote:
15 >> Hi!
16 >>
17 >>> On Wed, Mar 28, 2018 at 06:06:00PM +0100, Robert Sharp wrote:
18 >>> Does anyone know of a good, post GRSecurity guide to reasonable security
19 >>> for the kernel? In the absence of anything else I will have to go back
20 >>> to the KSPP list and start removing stuff until I can get a stable kernel.
21 >>
22 >> I'm using https://github.com/minipli/linux-unofficial_grsec, but it lacks
23 >> Spectre and Meltdown mitigation at the moment (see issues). Still, I
24 >> believe it's the best we can have now (better is probably paid GrSec, but
25 >> AFAIK it's impossible or too costly to buy it for home or small business).
26 >
27 > Previous contributors have access to the code, but it doesn't seem
28 > like there is any way to go that route anymore.
29 >

Replies

Subject Author
Re: [gentoo-hardened] Hardening a Kernel post hardened-sources Robert Sharp <selinux@×××××××××××××××.org>