Gentoo Archives: gentoo-hardened

From: Robert Sharp <selinux@×××××××××××××××.org>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Hardening a Kernel post hardened-sources
Date: Wed, 28 Mar 2018 17:06:09
Message-Id: 2462a2f5-b1dd-7ecd-b10f-ea32fc93688d@sharp.homelinux.org
1 Hi,
2
3 I still have hardened-sources running on one PC and I keep trying to
4 compile a replacement gentoo-sources with as much hardening as I can,
5 but I haven't found anything to help me that actually works. There are
6 some guides on the Internet but most of the them are quite old (still
7 grsecurity) and some of them are really old (Kernel 2.2, for example).
8
9 I found the KSPP website and built a kernel using their suggested
10 "paranoid" settings. It worked for a brief moment but then I think I
11 upgraded gcc to 6.4 and it just panicked during boot causing a lot of
12 pain to reverse out of.
13
14 Does anyone know of a good, post GRSecurity guide to reasonable security
15 for the kernel? In the absence of anything else I will have to go back
16 to the KSPP list and start removing stuff until I can get a stable kernel.
17
18 Thanks in advance,
19
20 Robert Sharp

Replies

Subject Author
Re: [gentoo-hardened] Hardening a Kernel post hardened-sources Alex Efros <powerman@××××××××.name>