Gentoo Archives: gentoo-hardened

From: Mansour Moufid <mansourmoufid@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] to chroot or not to chroot
Date: Wed, 10 Jun 2009 21:04:41
Message-Id: 44a1f4d20906101403s1756ba7eveb6437c7292beb46@mail.gmail.com
In Reply to: Re: [gentoo-hardened] to chroot or not to chroot by Jan Klod
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 On Wed, Jun 10, 2009 at 4:19 PM, Jan Klod<janklodvan@×××××.com> wrote:
5 > Well, I have such a kernel right now and quite likely, there is no need to
6 > rebuild it. I only lack some good information about how to set that Apache
7 > chroot up properly. Honestly I now tend to assume, my server is and will be
8 > only a mortal one, so I even consider just running it plainly. But if thats
9 > not an overkill, I'd like to jail Apache! Maybe you have some link...?
10
11 This may or may not be what you're looking for, but Portage does have
12 the new "mod_chroot" (www-apache/mod_chroot) [1]:
13
14 "mod_chroot allows you to run Apache in a chroot jail with no
15 additional files. The chroot() system call is performed at the end of
16 startup procedure - when all libraries are loaded and log files open."
17
18 [1] http://packages.gentoo.org/package/www-apache/mod_chroot?full_cat
19
20 - --
21 Mansour Moufid
22 http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x95BBC25F
23 -----BEGIN PGP SIGNATURE-----
24 Version: GnuPG v1.4.9 (GNU/Linux)
25 Comment: Use GnuPG with Firefox : http://getfiregpg.org (Version: 0.7.5)
26
27 iEYEARECAAYFAkowH34ACgkQ83JwsZW7wl/wHQCdGwZfWLe+7Fvi9UjfJV+HkfQh
28 zeUAoOt6fuEBRKaB+2kU8fDhAJq7Daux
29 =HOi2
30 -----END PGP SIGNATURE-----