1 |
Kevin F. Quinn wrote: |
2 |
> On Tue, 04 Jul 2006 18:34:25 +0200 |
3 |
> pageexec@××××××××.hu wrote: |
4 |
> |
5 |
> |
6 |
>> On 4 Jul 2006 at 16:19, Michael Decker wrote: |
7 |
>> |
8 |
>>> But I've detect that RSBAC and PAX manual are different, could be |
9 |
>>> here an error? (showing only the differences here): |
10 |
>>> http://www.gentoo.org/proj/en/hardened/rsbac/quickstart.xml |
11 |
>>> |
12 |
>>> --- SNIP --- |
13 |
>>> PaX Control ---> |
14 |
>>> [*] Support soft mode (Turn that option off on a production |
15 |
>>> kernel) [ ] Use legacy ELF header marking |
16 |
>>> [ ] Use ELF program header marking |
17 |
>>> Use ELF program header marking MAC system integration (direct) |
18 |
>>> ---> (X) direct |
19 |
>>> |
20 |
>> the problem is the MAC integration setting, for RSBAC you need |
21 |
>> the 'hook' type (i added it explicitly per Amon's request ;-), |
22 |
>> and the gentoo guide is wrong on this. the PaX guide suggests |
23 |
>> 'none' because it's, well, a PaX-only guide hence there's no |
24 |
>> MAC integration. |
25 |
>> |
26 |
> |
27 |
> Documentation fixed :) |
28 |
> |
29 |
> |
30 |
Sorry for the late reply, but actually RSBAC works with both direct and |
31 |
hook. At the time of writting the doc, the author priviligied "direct" |
32 |
and still does AFAIK. Although both seems to work equally well. |
33 |
|
34 |
See http://www.rsbac.org/pipermail/rsbac/2006-July/001869.html |
35 |
-- |
36 |
gentoo-hardened@g.o mailing list |