1 |
>> >> What else would you recommend for me? |
2 |
>> > |
3 |
>> > I'd suggest to completely ignore the grsec (low/med/high) options and |
4 |
>> > use the Hardened Gentoo level in the hardened-sources all the time. |
5 |
>> > |
6 |
>> > Xorg should not cause problems unless you are stuck using 3rd party |
7 |
>> > binary drivers. Most of us are using a hardened X setup. |
8 |
>> |
9 |
>> Excellent, thank you. You think the "Hardened Gentoo (workstation)" |
10 |
>> and "Hardened Gentoo (server)" grsecurity setups are adequate |
11 |
>> low-maintenance solutions? |
12 |
> |
13 |
> |
14 |
> Re: "low maintenance" |
15 |
> I'm not sure we can dumb down the hardening efforts anymore than we |
16 |
> already have. It's all pretty transparent and seems mostly like a normal |
17 |
> install of anything else. The ELF's are just smarter. |
18 |
|
19 |
Low maintenance definitely. Is the security OK? |
20 |
|
21 |
>> What does a hardened profile do for my server? |
22 |
> |
23 |
> Enables things to match the kernel options/blocks things that conflict. |
24 |
|
25 |
Is the grsecurity "Hardened Gentoo (workstation)" setting useful |
26 |
without the hardened profile? |
27 |
|
28 |
- Grant |