Gentoo Archives: gentoo-hardened

From: "Anthony G. Basile" <basile@××××××××××××××.edu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] New Server, considering hardened, need pointers to tfm...
Date: Mon, 12 Dec 2011 11:59:56
Message-Id: 4EE5ECA2.1060805@opensource.dyc.edu
In Reply to: Re: [gentoo-hardened] New Server, considering hardened, need pointers to tfm... by Kevin Chadwick
1 On 12/11/2011 03:30 PM, Kevin Chadwick wrote:
2 > On Sun, 11 Dec 2011 10:18:51 +0000
3 > Sven Vermeulen wrote:
4 >
5 >> Also consider hardening your system settings-wise. I would appreciate if you
6 >> take a look at
7 >> http://dev.gentoo.org/~swift/docs/previews/oval/gentoo-xccdf-guide.html.
8 >> With the instructions given, you can even have your system validated (as far
9 >> as possible) automatically.
10 >
11 > I was expecting to find here what one distro uses which is binary
12 > signature checking upon execution.
13 >
14 > Another thing that I try to do as a better method of TPE which is a
15 > breeze on OpenBSD and sometimes I find myself working against Linux
16 > developers¹ is to make it so that any writeable area of the filesystem
17 > is mounted noexec and mounts have the least priviledges required.
18 >
19 >
20 > ¹ "https://bugs.launchpad.net/ubuntu/+source/udisks/+bug/880965"
21 > set as won't fix and also e.g. apt-get expecting /tmp exec.
22
23 How would you handle /etc/ ? You can't separate it from / which needs
24 to be exec and yet /etc/ needs to be writeable.
25
26 --
27 Anthony G. Basile, Ph. D.
28 Chair of Information Technology
29 D'Youville College
30 Buffalo, NY 14201
31 (716) 829-8197

Replies

Subject Author
Re: [gentoo-hardened] New Server, considering hardened, need pointers to tfm... Kevin Chadwick <ma1l1ists@××××××××.uk>