Gentoo Archives: gentoo-hardened

From: basile <basile@××××××××××××××.edu>
To: tinhat@××××××××××××××.edu, gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Tin Hat 20090727 is out
Date: Mon, 27 Jul 2009 15:05:48
Message-Id: 4A6DC242.80306@opensource.dyc.edu
1 Hello everyone,
2
3 I'd like to announce that a new release of Tin Hat is out. Tin Hat is a fully featured Linux desktop based on Hardened Gentoo which runs purely in RAM. It aims to be very secure, stable, and fast.
4
5 This release continues the work of hardening the system libraries and binaries begun in the previous release with little changes to the kernel. The toolchain, composed of binutils-2-18, glibc-2.9 and gcc-4.3.3, was used to compile the system from scratch with the following hardening: 1) -fstack-protector-all for everything excpet glibc and evolution where just -fstack-protect is required, 2) -D_FORTIFY_SOURCE=2, 3) PIC/PIE, 4) -Wl,-z,now,-z,relro except for evolution which requires -z,lazy. These features were applied via CFLAGS/CXXFLAGS and LDFLAGS in the make.conf file in anticipation of migrating them to gcc's specs. We also sync-ed upstream with Gentoo, updating approximately 90 packages.
6
7 Home page: http://opensource.dyc.edu/tinhat
8 Downloads: http://opensource.dyc.edu/tinhat-downloads
9
10
11 Thanks to Zorry for helping me understand many of the issues.
12
13 --
14
15 Anthony G. Basile, Ph.D.
16 Chair of Information Technology
17 D'Youville College
18 Buffalo, NY 14201
19 USA
20
21 (716) 829-8197

Attachments

File name MIME type
signature.asc application/pgp-signature