Gentoo Archives: gentoo-hardened

From: "Javier Martínez" <tazok.id0@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] hardened workstation - is that worth it?
Date: Fri, 05 Dec 2008 17:21:52
Message-Id: 897813410812050921k1985ae7ar7caf712993423bc3@mail.gmail.com
In Reply to: Re: [gentoo-hardened] hardened workstation - is that worth it? by pageexec@freemail.hu
1 Have you said me that I'm obsoleted?, ok, I agreed with you... o:),
2 but since I don't use xorg in servers... no problem. You still having
3 the other problems I commented. One question, somebody knows what made
4 xorg incompatible with pax mprotect restrictions in earlier versions?.
5
6 I put you a link that is newer than the link that Brian Kroth posted
7 and still having the incompatibilities on:
8 http://www.gentoo.org/proj/en/hardened/pax-quickstart.xml, maybe a
9 mistake?
10 2008/12/5 <pageexec@××××××××.hu>:
11 > On 25 Nov 2008 at 21:36, Javier Martínez wrote:
12 >
13 >> In my opinion getting X-window running is bad in security concerns, by
14 >> this reasons:
15 >> - First: PaX should be disable in mprotect terms since Xorg needs it
16 >> (with it refuse to run) .
17 >
18 > - PaX flags: -------x-e-- [/usr/bin/Xorg]
19 >
20 > and it works for me... so why do you need to disable MPROTECT on your Xorg?
21 >
22 >
23 >

Replies

Subject Author
Re: [gentoo-hardened] hardened workstation - is that worth it? "Javier Martínez" <tazok.id0@×××××.com>
Re: [gentoo-hardened] hardened workstation - is that worth it? pageexec@××××××××.hu