Gentoo Archives: gentoo-hardened

From: Ned Ludd <solar@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Xen and Grsecurity
Date: Thu, 14 Dec 2006 22:07:07
Message-Id: 1166133879.8712.52.camel@onyx.private.gni.com
In Reply to: Re: [gentoo-hardened] Xen and Grsecurity by Simone Vallero
1 On Thu, 2006-12-14 at 22:35 +0100, Simone Vallero wrote:
2 > Alle 22:27, giovedì 14 dicembre 2006, Ned Ludd ha scritto:
3 >
4 > > > so i have to go on the SeLinux way? i can't see a x86_64 / hardened /
5 > > > selinux profile (the only that i can see is a 2005.1 x86
6 > > > hardened/selinux)
7 > >
8 > > I'm sorry but I have no idea what you are asking. Rather how you jumped
9 > > from xen+grsec to selinux. They are completely different things with
10 > > different goals.
11 > >
12 > > Please read http://www.gentoo.org/proj/en/hardened/primer.xml
13 > >
14 >
15 > i need security... i'm using grsec since 2.4 kernels on all my servers, but
16 > now, i'm migrating to Xen and so i don't like to remain without 'hardening
17 > features'
18 > i know that grsec and selinux are different things, but the question is:
19 > it is possible to have an hardened toolchain (ssp/pie) with a selinux profile
20 > on amd64?
21
22 Yes but it requires using patches found in our bugzilla.
23 I'm guessing they will be in the tree within a few weeks.
24
25
26 >
27 > bye
28 >
29 --
30 Ned Ludd <solar@g.o>
31 Gentoo Linux
32
33 --
34 gentoo-hardened@g.o mailing list