Gentoo Archives: gentoo-hardened

From: Brian Kroth <bpkroth@××××.edu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] hardened glibc-2.5 issues
Date: Sun, 17 Jun 2007 14:25:52
Message-Id: 467543FB.80502@wisc.edu
In Reply to: Re: [gentoo-hardened] hardened glibc-2.5 issues by Adam Lantos
1 I experienced problems while testing slapd and pam_ldap when I
2 originally updated to glibc-2.5* - hardened profile for me. Recompiles
3 fixed it.
4
5 BTW, I may be wrong in this ideology, but since gentoo is a from source
6 distro, in general I'd try recompiling dependencies of the offending
7 package before mucking about in the kernel - that seems like it would
8 affect everything rather than just a couple of packages, thus making
9 your troubleshooting that much more difficult.
10
11 Brian
12
13 Adam Lantos wrote:
14 > recompiling glibc-2.5-r3 (USE="-nptl -nptlonly hardened") and db,
15 > openldap solved the issue.
16 >
17 >
18 > On 6/17/07, Adam Lantos <hege@××××××.org> wrote:
19 >> no, it wasn't me, and it wasn't PaX either. Kernel is
20 >> 2.6.18-grsec-pax, and mysql and openldap worked well since half a
21 >> year... PaX works well, and logs well when it kicks in.
22 >>
23 >> another issue that could be related to this: sshd communication
24 >> processes die randomly. nothing there in syslog/kernel log.
25 >>
26 >>
27 >> yours,
28 >> adam
29 >>
30 >>
31 >> On 6/17/07, pageexec@××××××××.hu <pageexec@××××××××.hu> wrote:
32 >> > On 16 Jun 2007 at 23:49, Adam Lantos wrote:
33 >> >
34 >> > > [pid 11694] +++ killed by SIGKILL +++
35 >> >
36 >> > if that SIGKILL wasn't you, it could have been PaX (if you're using
37 >> it),
38 >> > can you check your kernel logs for PaX messages?
39 >> >
40 >> >
41 >> > --
42 >> > gentoo-hardened@g.o mailing list
43 >> >
44 >> >
45 >>

Attachments

File name MIME type
smime.p7s application/x-pkcs7-signature

Replies

Subject Author
Re: [gentoo-hardened] hardened glibc-2.5 issues Adam Lantos <hege@××××××.org>