Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: "Christian Schäfer" <caefer@××××××××××.net>
Cc: Hardened Gentoo Mail List <gentoo-hardened@g.o>
Subject: Re: Re[2]: [gentoo-hardened] getting started..
Date: Fri, 15 Aug 2003 18:24:29
Message-Id: 1060971867.1909.77.camel@chris.pebenito.net
In Reply to: Re[2]: [gentoo-hardened] getting started.. by "Christian Schäfer"
1 Well theres two of reiserfsck being sloppy on the getattrs on
2 /dev/random and /dev/ppp, that I can add into the base policy. It
3 looks like /tmp is mislabeled by looking at the 3rd-9th denial. Files
4 shouldn't normally be file_t. Looks like your syslog-ng is logging to
5 tty12, there is a rule in syslogd.te that can be uncommented for that.
6 Based on the agetty denials, I would guess that you have the networking
7 hooks turned on in the kernel config, and you should turn them off.
8
9 The best time in the IRC channel for help would probably be during the
10 day in the US, say 10am-midnight UTC -5.
11
12 On Fri, 2003-08-15 at 12:29, Christian Schäfer wrote:
13 > Well, I did 'make relabel' when starting my new system.
14 > I attached the output of dmesg to this mail, maybe you will find, what
15 > you need.
16 >
17 > assuming that most people on this list are also on the irc channel,
18 > when would you say is the best daytime to ask for help?
19 > as long as I am only gathering informations I will stick to the
20 > mailinglist but when it comes to work, I will most likely need
21 > realtime help. ;-)
22
23 --
24 Chris PeBenito
25 <pebenito@g.o>
26 Developer, SELinux
27 Hardened Gentoo Linux
28
29 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
30 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re[4]: [gentoo-hardened] getting started.. "Christian Schäfer" <caefer@××××××××××.net>