Gentoo Archives: gentoo-hardened

From: Brian Kroth <bpkroth@×××××.com>
To: pageexec@××××××××.hu
Cc: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] hardened workstation - is that worth it?
Date: Fri, 05 Dec 2008 16:38:59
Message-Id: 20081205163851.GL24099@gmail.com
In Reply to: Re: [gentoo-hardened] hardened workstation - is that worth it? by pageexec@freemail.hu
1 pageexec@××××××××.hu <pageexec@××××××××.hu> 2008-12-05 17:29:
2 > On 25 Nov 2008 at 21:36, Javier Martínez wrote:
3 >
4 > > In my opinion getting X-window running is bad in security concerns, by
5 > > this reasons:
6 > > - First: PaX should be disable in mprotect terms since Xorg needs it
7 > > (with it refuse to run) .
8 >
9 > - PaX flags: -------x-e-- [/usr/bin/Xorg]
10 >
11 > and it works for me... so why do you need to disable MPROTECT on your Xorg?
12
13
14 Right. The bottom of this page says that's no longer necessary, and it
15 hasn't been updated for a long time:
16
17 http://www.gentoo.org/proj/en/hardened/hardenedxorg.xml