Gentoo Archives: gentoo-hardened

From: Gordon Malm <gengor@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Grsecurity slows down a web server?
Date: Fri, 23 Jan 2009 18:38:36
Message-Id: 200901231038.31451.gengor@gentoo.org
In Reply to: Re: [gentoo-hardened] Grsecurity slows down a web server? by Grant
1 Try 'pspax'. If there is no NX bit and you enable both PAGEEXEC and SEGMEXEC
2 it should not be using PAGEEXEC.
3
4 http://www.bumpin.org/pics/PaX/pax_performance-2.6.24.png
5
6 Gordon Malm (gengor)
7
8 On Friday, January 23, 2009 10:14:11 Grant wrote:
9 > > [snip]
10 > >
11 > >> menuconfig isn't letting me disable PAGEEXEC. Maybe it's tied to
12 > >> grsecurity "Gentoo (server)"? I don't want to disable that. Maybe I
13 > >> should live with the slowdown?
14 > >
15 > > No you should not.
16 > >
17 > > After selecting server and saving it. You want to then select "Custom"
18 > > that will leave all the options enabled from "server". You then scroll
19 > > over to the PaX menu and de-select PAGE and select SEGM.
20 > >
21 > > Easy as pie. Good luck.
22 >
23 > Alright, thank you. PAGEEXEC and SEGMEXEC are both selected via
24 > Gentoo (server) so I disabled PAGEEXEC. Should I submit a bug too?
25 >
26 > - Grant

Replies

Subject Author
Re: [gentoo-hardened] Grsecurity slows down a web server? Grant <emailgrant@×××××.com>