Gentoo Archives: gentoo-hardened

From: Grant <emailgrant@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Profile switch: hardened to non-hardened?
Date: Tue, 30 Dec 2008 20:31:12
Message-Id: 49bf44f10812301231v4b1223d2le83703473a04b98f@mail.gmail.com
In Reply to: Re: [gentoo-hardened] Profile switch: hardened to non-hardened? by Ned Ludd
1 >> >> What else would you recommend for me?
2 >> >
3 >> > I'd suggest to completely ignore the grsec (low/med/high) options and
4 >> > use the Hardened Gentoo level in the hardened-sources all the time.
5 >> >
6 >> > Xorg should not cause problems unless you are stuck using 3rd party
7 >> > binary drivers. Most of us are using a hardened X setup.
8 >>
9 >> Excellent, thank you. You think the "Hardened Gentoo (workstation)"
10 >> and "Hardened Gentoo (server)" grsecurity setups are adequate
11 >> low-maintenance solutions?
12 >
13 >
14 > Re: "low maintenance"
15 > I'm not sure we can dumb down the hardening efforts anymore than we
16 > already have. It's all pretty transparent and seems mostly like a normal
17 > install of anything else. The ELF's are just smarter.
18
19 Low maintenance definitely. Is the security OK?
20
21 >> What does a hardened profile do for my server?
22 >
23 > Enables things to match the kernel options/blocks things that conflict.
24
25 Is the grsecurity "Hardened Gentoo (workstation)" setting useful
26 without the hardened profile?
27
28 - Grant

Replies