Gentoo Archives: gentoo-hardened

From: Miguel Figueiredo Mascarenhas Sousa Filipe <miguel.filipe@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Reducing the number of setuids, root user daemons..et al
Date: Wed, 11 Oct 2006 12:49:31
Message-Id: f058a9c30610110547i71f26077qbf060cc31b8e66a1@mail.gmail.com
In Reply to: Re: [gentoo-hardened] Reducing the number of setuids, root user daemons..et al by Matthias Bethke
1 Hi,
2
3 On 10/11/06, Matthias Bethke <matthias@×××××××.de> wrote:
4 > Hi Miguel,
5 > on Tuesday, 2006-10-10 at 11:35:49, you wrote:
6 > > >> One interesting Idea would be to use the /etc/shadow replacement that
7 > > >> is present in openwall
8 > > >
9 > > >Not something I've looked at. Could you describe this a bit more?
10 > >
11 > > I will, in the meantime, let me just point out to the "homepage" of
12 > > the "project":
13 > > http://www.openwall.com/tcb/
14 >
15 > Sounds like an interesting concept! But it's already in portage
16 > (sys-apps/tcb) so chances are somebody has tried it? I wonder how it
17 > integrates with NIS. Guess some changing of the map-updating Makefile
18 > should do it.
19 >
20
21 It's on my TODO list, next to dhclient drop-root-priv patch.. ... ;-)
22
23 > cheers!
24 > Matthias
25 > --
26 > I prefer encrypted and signed messages. KeyID: FAC37665
27 > Fingerprint: 8C16 3F0A A6FC DF0D 19B0 8DEF 48D9 1700 FAC3 7665
28 >
29 >
30 >
31
32
33 --
34 Miguel Sousa Filipe
35 --
36 gentoo-hardened@g.o mailing list