Gentoo Archives: gentoo-hardened

From: "Christian Schäfer" <caefer@××××××××××.net>
To: Chris PeBenito <pebenito@g.o>
Cc: Hardened Gentoo Mail List <gentoo-hardened@g.o>
Subject: Re[6]: [gentoo-hardened] getting started..
Date: Sat, 16 Aug 2003 16:14:10
Message-Id: 789164978.20030816181243@krachstoff.net
In Reply to: Re: Re[4]: [gentoo-hardened] getting started.. by Chris PeBenito
1 hi Chris,
2
3 > > > Well theres two of reiserfsck being sloppy on the getattrs on
4 > > > /dev/random and /dev/ppp, that I can add into the base policy.
5 > > and where can I fix that behaviour?
6 > in fsadm.te:
7 > dontaudit fsadm_t random_device_t:chr_file getattr;
8 > dontaudit fsadm_t ppp_device_t:chr_file getattr;
9
10 ok, I found that and added these two lines. *curious*
11
12 > Under the security options menu:
13 > [ ] Socket and Networking Security Hooks
14 ah, ok. you were right, that option was turned on, so I turned it off.
15 now the kernel is just recompiling.
16
17 > Depends on what the filesystem /tmp is. Since files in /tmp are file_t,
18 > its probably not tmpfs, so just relabel.
19 well, /tmp is a partition running reiserfs.
20 I did a 'make relabel', let's see where that will get me..
21
22 I will send another mail, when the system is booted with the new
23 kernel then.
24
25
26 gruss
27 /Christian mailto:caefer@××××××××××.net
28
29 ---
30
31
32 I propose that the following character sequence for joke markers:
33
34 :-)
35
36 19-Sep-82 11:44 Scott E Fahlman
37
38
39 --
40 gentoo-hardened@g.o mailing list