Gentoo Archives: gentoo-hardened

From: basile <basile@××××××××××××××.edu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Re: Tin Hat 20090119 released
Date: Fri, 23 Jan 2009 00:28:50
Message-Id: 49790F3E.7070801@opensource.dyc.edu
In Reply to: [gentoo-hardened] Re: Tin Hat 20090119 released by 7v5w7go9ub0o <7v5w7go9ub0o@gmail.com>
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4
5 Hi everyone,
6
7 Let me respond to all in one email:
8
9
10 7v5w7go9ub0o wrote:
11 > THANK YOU for taking the time to post this valuable information!
12 > Thanks also for sharing your infectious energy with this mailing
13 > list; it reinforces the importance of keeping hardened Gentoo
14 > vital!!
15
16 Hardened Gentoo is *very* important and I think the team would appreciate
17 knowing where their work ends up: Besides being the basis of Tin Hat,
18 it is
19 also the basis of another project of ours (tor-ramdisk) which uses a
20 uclibc
21 (not glibc) based hardened gentoo environment to securely house a tor
22 relay.
23 Three of our production servers at D'Youville College are hardened gentoo
24 (virtual.dyc.edu, moodle.dyc.edu and project.dyc.edu) as are a couple of
25 internal servers. I use hardened gentoo when I teach my security course
26 to demonstrate various hardening techniques.
27
28 Clearly, we are heavily invested users. Yes, keep hardened Gentoo vital!
29
30
31 Gordon Malm wrote:
32 > I think Tin Hat is a cool project and they are more than welcome to
33 >
34 keep us
35 > abreast of new releases, along with some short release notes. In
36 fact, I am
37 > glad they do. It is hardly spam. Thanks Tin Hat peeps and keep up
38 >
39 the good
40 > work!
41 >
42 > Gordon Malm (gengor)
43
44 Thanks Gordon. On another note, I am wondering if you and the other
45 team members
46 have any thoughts about PaX/Grsecurity possibly being dropped
47 upstream. I hate
48 to see harndened gentoo without it, but there may be no choice.
49
50
51 RijilV wrote:
52 >
53 > On a side note, I think a stripped down version of tin hat linux
54 would be
55 > really cool - something around 300-400megs (so it could run very
56 nice on a
57 > system with a gig of ram).
58
59 We were already discussing this for the reasons you mention.
60
61
62 Anthony Basile, Ph.D.
63 Chair of Information Technology
64 D'Youville College
65 Buffalo, NY 14201
66 USA
67
68
69 -----BEGIN PGP SIGNATURE-----
70 Version: GnuPG v1.4.9 (GNU/Linux)
71 Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
72
73 iEYEARECAAYFAkl5Dz0ACgkQl5yvQNBFVTVm9gCeM8/Zn32Lxb+LgTMQfJoJaOdj
74 pRwAnRHIFB9JSFhsnV/oPNS15AdRLKFZ
75 =jYHx
76 -----END PGP SIGNATURE-----

Replies

Subject Author
Re: [gentoo-hardened] Re: Tin Hat 20090119 released Ned Ludd <solar@g.o>
Re: [gentoo-hardened] Re: Tin Hat 20090119 released pageexec@××××××××.hu