Gentoo Archives: gentoo-hardened

From: Sadako <sadako@××××××××××××××.ca>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] KVM & Gentoo Hardened
Date: Sun, 21 Dec 2008 16:21:35
Message-Id: 891aebf1f2cc377adba08adebc77c120.squirrel@www.hamiltonshells.ca
In Reply to: Re: [gentoo-hardened] KVM & Gentoo Hardened by "Javier J. Martínez Cabezón"
1 > I have one virtualbox using VT extensions, and runs fine. I have used
2 > PaX in the guest with rsbac 1.3.7 and the noexec based on segmentation
3 > and all others on (peMRXS flags) and goes fine (with pageexec does not
4 > work, hangs at boot, so I switch segmexec). I think that you shouldn't
5 > have any troubles with kvm, if you have some try using virtualbox.
6 > I added -D_FORTIFY_SOURCE=2 to the cflags in make.conf compilation, it
7 > runs fine too and I think is safe. Not hangs at the moment.
8 >
9 > 2008/12/16 Romain BERGE <romain.berge@×××××.com>:
10 >> Hey all,
11 >>
12 >> I am wondering of using and AMD CPU with the AMD-V.
13 >> I wonder of using KVM to virtualise a few Hardened server.
14 >>
15 >> Someone used already KVM+ Hardened ?
16 >>
17 >> Working fine ?
18 >>
19 >> Thanks
20 >>
21 >> Regards
22 >>
23 >>
24 >
25 >
26 Do you actually have the virtualbox _host_ running under hardened-sources?
27 If so, could you please upload your kernel config somewhere?
28
29 I've been trying to do the same, but upon trying to boot a guest (any
30 guest) via virtualbox the host box locks up, and I've tried everything I
31 can think of, including disabling _all_ grsec and pax options within the
32 kernel...

Replies

Subject Author
Re: [gentoo-hardened] KVM & Gentoo Hardened "Javier J. Martínez Cabezón" <tazok.id0@×××××.com>
Re: [gentoo-hardened] KVM & Gentoo Hardened "Javier J. Martínez Cabezón" <tazok.id0@×××××.com>
Re: [gentoo-hardened] KVM & Gentoo Hardened Pavel Labushev <p.labushev@×××××.com>