Gentoo Archives: gentoo-hardened

From: Ned Ludd <solar@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Grsecurity slows down a web server?
Date: Fri, 23 Jan 2009 17:22:47
Message-Id: 1232731334.25551.3.camel@hangover
In Reply to: Re: [gentoo-hardened] Grsecurity slows down a web server? by Grant
1 On Fri, 2009-01-23 at 08:45 -0800, Grant wrote:
2 > >> >> My website seems a bit slower since I enabled grsecurity on that
3 > >> >> system. Is that typical? Is it most likely due to MPROTECT, or
4 > >> >> something else?
5 > >> >
6 > >> > can you quantify this slowdown? and what grsec/pax features did you enable?
7 > >>
8 > >> I enabled the grsecurity "Gentoo (server)" profile in the hardened
9 > >> kernel.
10 > >
11 > > ok, is PAGEEXEC enabled (and SEGMEXEC isn't) and is your cpu some P4 variant
12 > > without NX support? that's about the only situation where you should see an
13 > > observable slowdown, otherwise i doubt you can percieve a few % without
14 > > actual measurements. so if neither is your case, it's definitely worth an
15 > > investigation.
16 >
17 > Very close. PAGEEXEC is enabled, but so is SEGMEXEC. My CPU is a
18 > P4-2.8, and I'm not sure about NX support but these are the flags:
19
20
21 Disable PAGEEXEC and switch to SEGMEXEC on the P4. That slowdown will go
22 away. No idea why on earth the (server) options would enable such a
23 thing on the x86 platform.
24
25 --
26 Ned Ludd <solar@g.o>
27 Gentoo Linux

Replies

Subject Author
Re: [gentoo-hardened] Grsecurity slows down a web server? Grant <emailgrant@×××××.com>