1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
|
5 |
I'd recommend that you familiarize yourself with the documentation before |
6 |
trying out the learning mode. It's not in the best state right now, but |
7 |
there is enough there to get an idea where to start. Learning mode uses a |
8 |
learning configuration file. Based on this file, grsec will build rules |
9 |
based on the activity it sees when in learning mode (e.g. if your |
10 |
unprivilaged user runs "passwd", grsec will see all the files that are |
11 |
executed/read/appended to/etc and then add it to the role for that user). |
12 |
Tweaking the policy can take some time; a good approach would be to watch |
13 |
/var/log/grsec.log when activating the RBAC system. This way, you can |
14 |
determine what is too locked down (e.g. access to /etc/localtime) and |
15 |
correct it. |
16 |
|
17 |
IMHO, it's great to use. Unfortunately, I don't have a policy handy, but |
18 |
you can find a decent example one at: |
19 |
|
20 |
http://forums.grsecurity.net/viewtopic.php?p=5555& |
21 |
|
22 |
Documentation can be found at: |
23 |
|
24 |
http://hardened.gentoo.org |
25 |
http://www.grsecurity.net/papers.php |
26 |
|
27 |
Hope that helps; sorry I don't have an actual policy to show ATM... |
28 |
|
29 |
- -Brant |
30 |
|
31 |
Public GPG/PGP key for Brant Williams: 0x88E1AA9E. |
32 |
Available at your friendly local public keyserver. |
33 |
|
34 |
|
35 |
|
36 |
On Sun, 29 Oct 2006, Brian Davis wrote: |
37 |
|
38 |
> So maybe I'm missing something. Is learning mode all you need to do to get up |
39 |
> and running? How much time did you spend tweaking the profile? Is it a |
40 |
> security no-no to ask to see your profile. |
41 |
> |
42 |
> Thanks, |
43 |
> Brian |
44 |
> |
45 |
> ----- Original Message ----- From: <atoth@××××××××××.hu> |
46 |
> To: <gentoo-hardened@l.g.o> |
47 |
> Sent: Sunday, October 29, 2006 11:37 AM |
48 |
> Subject: Re: [gentoo-hardened] Re: Do I need RBAC? |
49 |
> |
50 |
> |
51 |
> > On Vas, Október 29, 2006 16:19, 7v5w7go9ub0o wrote: |
52 |
> > > If you are talking about Grsecurity (which has a learning mode that makes |
53 |
> > > configuration very easy), and if your users are doing limited, standard |
54 |
> > > things, then a strong Yes! (though IIUC, SeLinux is difficult to |
55 |
> > > configure) |
56 |
> > Strongly agree. |
57 |
> > |
58 |
> > I use Grsecurity even on my laptop, which has only one non-root user: me. |
59 |
> > You can call me paranoid, but it's good to know, that my computer is |
60 |
> > protected from myself... |
61 |
> > |
62 |
> > Regards, |
63 |
> > Dw. |
64 |
> > |
65 |
> > -- |
66 |
> > dr Tóth Attila, Radiológus Szakorvos jelölt, 06-20-825-8057, 06-30-5962-962 |
67 |
> > Attila Toth MD, Radiologist in Training, +36-20-825-8057, +36-30-5962-962 |
68 |
> > |
69 |
> > > |
70 |
> > > The RBAC protection will protect you if -you- or a trusted user does |
71 |
> > > something accidentally (e.g. shell command), or downloads something that |
72 |
> > > tries to exploit a news client or browser. It may also protect you if |
73 |
> > > someone ever compromises a portage distribution. |
74 |
> > > |
75 |
> > > There seems to be a reluctance among some old-timers to use the hardened |
76 |
> > > tools anywhere else but on a server - I'd guess that is a holdover from |
77 |
> > > the last decade when both Linux and the hardening tools were being |
78 |
> > > created. Today's (non-selinux) tools are easy to use, and are IMHO quite |
79 |
> > > appropriate for home use in today's world of professional crackers going |
80 |
> > > after home users. Heh, even MS is "hardening" their new OS, VISTA. |
81 |
> > > |
82 |
> > > |
83 |
> > > On Sun, 29 Oct 2006 00:16:59 -0400, |
84 |
> > > <bridavis-Wuw85uim5zDR7s880joybQ@××××××××××××.org> wrote: |
85 |
> > > |
86 |
> > > > I have a total of 3 non-root users, 1 is me, the 2 others are trusted |
87 |
> > > > (i.e. family/friend). RBAC looks like it's more complex that I need and |
88 |
> > > > want to deal with, and I'm I'm wondering if I should bother with this |
89 |
> > > > with so few users. |
90 |
> > > > |
91 |
> > > > Thoughts? |
92 |
> > > > |
93 |
> > > > Thanks, |
94 |
> > > > Brian |
95 |
> > > |
96 |
> > > |
97 |
> > > -- |
98 |
> > > gentoo-hardened@g.o mailing list |
99 |
> > > |
100 |
> > |
101 |
> > |
102 |
> > -- |
103 |
> > gentoo-hardened@g.o mailing list |
104 |
> > |
105 |
> |
106 |
> -- |
107 |
> gentoo-hardened@g.o mailing list |
108 |
> |
109 |
> |
110 |
-----BEGIN PGP SIGNATURE----- |
111 |
Version: GnuPG v1.4.5 (GNU/Linux) |
112 |
|
113 |
iD8DBQFFRZgHYfOV94jhqp4RAqDIAJ9P2wYWJuv5ne6uHXd5vlcaSGFeaACfVrBC |
114 |
rUKcC8pCHivqrpnXkVUU0wc= |
115 |
=vchO |
116 |
-----END PGP SIGNATURE----- |