Gentoo Archives: gentoo-hardened

From: Grant <emailgrant@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Grsecurity slows down a web server?
Date: Fri, 23 Jan 2009 16:45:21
Message-Id: 49bf44f10901230845u4c34d6c7ia546fcda81542661@mail.gmail.com
In Reply to: Re: [gentoo-hardened] Grsecurity slows down a web server? by pageexec@freemail.hu
1 >> >> My website seems a bit slower since I enabled grsecurity on that
2 >> >> system. Is that typical? Is it most likely due to MPROTECT, or
3 >> >> something else?
4 >> >
5 >> > can you quantify this slowdown? and what grsec/pax features did you enable?
6 >>
7 >> I enabled the grsecurity "Gentoo (server)" profile in the hardened
8 >> kernel.
9 >
10 > ok, is PAGEEXEC enabled (and SEGMEXEC isn't) and is your cpu some P4 variant
11 > without NX support? that's about the only situation where you should see an
12 > observable slowdown, otherwise i doubt you can percieve a few % without
13 > actual measurements. so if neither is your case, it's definitely worth an
14 > investigation.
15
16 Very close. PAGEEXEC is enabled, but so is SEGMEXEC. My CPU is a
17 P4-2.8, and I'm not sure about NX support but these are the flags:
18
19 fpu vme de pse tsc msr pae mce cx8 apic mtrr pge mca cmov pat pse36
20 clflush dts acpi mmx fxsr sse sse2 ss ht tm pbe constant_tsc pebs bts
21 pni monitor ds_cpl cid xtpr
22
23 - Grant

Replies

Subject Author
Re: [gentoo-hardened] Grsecurity slows down a web server? "René Rhéaume" <rene.rheaume@×××××.com>
Re: [gentoo-hardened] Grsecurity slows down a web server? Ned Ludd <solar@g.o>