Gentoo Archives: gentoo-hardened

From: Alex Efros <powerman@××××××××.name>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Hardening a Kernel post hardened-sources
Date: Wed, 28 Mar 2018 17:40:47
Message-Id: 20180328174039.GD31884@home.power
In Reply to: [gentoo-hardened] Hardening a Kernel post hardened-sources by Robert Sharp
1 Hi!
2
3 On Wed, Mar 28, 2018 at 06:06:00PM +0100, Robert Sharp wrote:
4 > Does anyone know of a good, post GRSecurity guide to reasonable security
5 > for the kernel? In the absence of anything else I will have to go back
6 > to the KSPP list and start removing stuff until I can get a stable kernel.
7
8 I'm using https://github.com/minipli/linux-unofficial_grsec, but it lacks
9 Spectre and Meltdown mitigation at the moment (see issues). Still, I
10 believe it's the best we can have now (better is probably paid GrSec, but
11 AFAIK it's impossible or too costly to buy it for home or small business).
12
13 --
14 WBR, Alex.

Replies

Subject Author
Re: [gentoo-hardened] Hardening a Kernel post hardened-sources R0b0t1 <r030t1@×××××.com>