Gentoo Archives: gentoo-hardened

From: Brant Williams <brant@×××××.net>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Re: Do I need RBAC?
Date: Mon, 30 Oct 2006 06:15:23
Message-Id: Pine.LNX.4.64.0610300002250.12353@surreal.mirage.org
In Reply to: Re: [gentoo-hardened] Re: Do I need RBAC? by Brian Davis
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4
5 I'd recommend that you familiarize yourself with the documentation before
6 trying out the learning mode. It's not in the best state right now, but
7 there is enough there to get an idea where to start. Learning mode uses a
8 learning configuration file. Based on this file, grsec will build rules
9 based on the activity it sees when in learning mode (e.g. if your
10 unprivilaged user runs "passwd", grsec will see all the files that are
11 executed/read/appended to/etc and then add it to the role for that user).
12 Tweaking the policy can take some time; a good approach would be to watch
13 /var/log/grsec.log when activating the RBAC system. This way, you can
14 determine what is too locked down (e.g. access to /etc/localtime) and
15 correct it.
16
17 IMHO, it's great to use. Unfortunately, I don't have a policy handy, but
18 you can find a decent example one at:
19
20 http://forums.grsecurity.net/viewtopic.php?p=5555&
21
22 Documentation can be found at:
23
24 http://hardened.gentoo.org
25 http://www.grsecurity.net/papers.php
26
27 Hope that helps; sorry I don't have an actual policy to show ATM...
28
29 - -Brant
30
31 Public GPG/PGP key for Brant Williams: 0x88E1AA9E.
32 Available at your friendly local public keyserver.
33
34
35
36 On Sun, 29 Oct 2006, Brian Davis wrote:
37
38 > So maybe I'm missing something. Is learning mode all you need to do to get up
39 > and running? How much time did you spend tweaking the profile? Is it a
40 > security no-no to ask to see your profile.
41 >
42 > Thanks,
43 > Brian
44 >
45 > ----- Original Message ----- From: <atoth@××××××××××.hu>
46 > To: <gentoo-hardened@l.g.o>
47 > Sent: Sunday, October 29, 2006 11:37 AM
48 > Subject: Re: [gentoo-hardened] Re: Do I need RBAC?
49 >
50 >
51 > > On Vas, Október 29, 2006 16:19, 7v5w7go9ub0o wrote:
52 > > > If you are talking about Grsecurity (which has a learning mode that makes
53 > > > configuration very easy), and if your users are doing limited, standard
54 > > > things, then a strong Yes! (though IIUC, SeLinux is difficult to
55 > > > configure)
56 > > Strongly agree.
57 > >
58 > > I use Grsecurity even on my laptop, which has only one non-root user: me.
59 > > You can call me paranoid, but it's good to know, that my computer is
60 > > protected from myself...
61 > >
62 > > Regards,
63 > > Dw.
64 > >
65 > > --
66 > > dr Tóth Attila, Radiológus Szakorvos jelölt, 06-20-825-8057, 06-30-5962-962
67 > > Attila Toth MD, Radiologist in Training, +36-20-825-8057, +36-30-5962-962
68 > >
69 > > >
70 > > > The RBAC protection will protect you if -you- or a trusted user does
71 > > > something accidentally (e.g. shell command), or downloads something that
72 > > > tries to exploit a news client or browser. It may also protect you if
73 > > > someone ever compromises a portage distribution.
74 > > >
75 > > > There seems to be a reluctance among some old-timers to use the hardened
76 > > > tools anywhere else but on a server - I'd guess that is a holdover from
77 > > > the last decade when both Linux and the hardening tools were being
78 > > > created. Today's (non-selinux) tools are easy to use, and are IMHO quite
79 > > > appropriate for home use in today's world of professional crackers going
80 > > > after home users. Heh, even MS is "hardening" their new OS, VISTA.
81 > > >
82 > > >
83 > > > On Sun, 29 Oct 2006 00:16:59 -0400,
84 > > > <bridavis-Wuw85uim5zDR7s880joybQ@××××××××××××.org> wrote:
85 > > >
86 > > > > I have a total of 3 non-root users, 1 is me, the 2 others are trusted
87 > > > > (i.e. family/friend). RBAC looks like it's more complex that I need and
88 > > > > want to deal with, and I'm I'm wondering if I should bother with this
89 > > > > with so few users.
90 > > > >
91 > > > > Thoughts?
92 > > > >
93 > > > > Thanks,
94 > > > > Brian
95 > > >
96 > > >
97 > > > --
98 > > > gentoo-hardened@g.o mailing list
99 > > >
100 > >
101 > >
102 > > --
103 > > gentoo-hardened@g.o mailing list
104 > >
105 >
106 > --
107 > gentoo-hardened@g.o mailing list
108 >
109 >
110 -----BEGIN PGP SIGNATURE-----
111 Version: GnuPG v1.4.5 (GNU/Linux)
112
113 iD8DBQFFRZgHYfOV94jhqp4RAqDIAJ9P2wYWJuv5ne6uHXd5vlcaSGFeaACfVrBC
114 rUKcC8pCHivqrpnXkVUU0wc=
115 =vchO
116 -----END PGP SIGNATURE-----