Gentoo Archives: gentoo-hardened

From: Jan Krueger <jk@×××××××××××.net>
To: method@g.o, gentoo-hardened@g.o
Subject: Re: [gentoo-hardened] Ports Security
Date: Fri, 05 Sep 2003 19:28:03
Message-Id: 200309052132.42706.jk@microgalaxy.net
In Reply to: Re: [gentoo-hardened] Ports Security by Joshua Brindle
1 On Friday 05 September 2003 18:34, Joshua Brindle wrote:
2 > based on the openbsd page you pasted, and my own intuitions i'll
3 > just say this isn't ever going to be done. There is no reason to
4 > add this kind of checking into the user side of portage.
5
6 Well, there is, for sure.
7
8 (The posted OpenBSD page defines a policy somehow and gives recommendations
9 for/to ports developers to make sure the resulting software doesnt comprise
10 the overall security of the system)
11
12 (gh=gentoo hardened)
13
14 Such a policy, from my point of view, is required for gh too.
15 It is too easy, eben with ProPolice, grsecurtiy, PaX whatever, to create a
16 open system by installing software that does the wrong thing.
17 (old classic: sendmail spawning uudecode overwriting /etc/passwd)
18
19 I, as a Sysadmin, on the other hand, dont have the time audit every package.
20 But at least, those tools would help me to estimate
21 1. if the software i would like to install is somehow risky
22 2. risky to what extend
23
24 So i can define a System/Site wide policy what ebuilds i accept an which not.
25
26 On the third hand it is impossible for gh to bring all >4000 ebuilds to a high
27 security level, also it is impossible to enforce a secure ebuild policy on
28 all contributers, some simply dont care. I dont care if unreal tournament is
29 secure or not, but i do care about other things, server related. For sure,
30 some important core stuff will be hardened, what about the rest?
31
32 So i as a sysadmin or user should have an easy way to check the possible
33 impact of an ebuild i would like install. and then i will decide: i do or
34 dont. I also would like to define a policy that allows install only of known
35 secure ebuilds and ebuilds that pass the checks.
36
37 A secure ebuild policy it would help to define gh.
38 All ebuilds (lets say maybe 100, base things) that implement this policy
39 belong to gh and are proven and userverifyablesecure.
40
41 Jan
42
43
44 --
45 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Ports Security Jan Krueger <jk@×××××××××××.net>