Gentoo Archives: gentoo-hardened

From: RB <aoz.syn@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] to chroot or not to chroot
Date: Wed, 10 Jun 2009 20:37:48
Message-Id: 4255c2570906101337n659369e2u50e926cbc07aa1fa@mail.gmail.com
In Reply to: Re: [gentoo-hardened] to chroot or not to chroot by Jan Klod
1 On Wed, Jun 10, 2009 at 14:19, Jan Klod<janklodvan@×××××.com> wrote:
2 > only a mortal one, so I even consider just running it plainly. But if thats
3 > not an overkill, I'd like to jail Apache! Maybe you have some link...?
4
5 If you'll note:
6
7 On Wed, Jun 10, 2009 at 08:24, RB<aoz.syn@×××××.com> wrote:
8 > chroot. Look at one of the many chroot() preparation tools available
9 > in portage (emerge -S chroot) for easy ways to set up clean chroot()
10 > environments without any missing libraries.
11
12 The three that stand out to me are app-admin/chroot_safe,
13 app-misc/jail, and dev-util/schroot (which is only in Sunrise at this
14 time). I have zero experience with any of them, (I run no chrootable
15 services), so I can't really speak to which is better than the others.