Gentoo Archives: gentoo-user

From: Gregory Woodbury <redwolfe@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] BOINC on a hardened system?
Date: Fri, 28 Jul 2017 19:23:20
Message-Id: CAJoOjx9xDr87CqwU0c93m6YaAHxGs9EdgEFGBR+QiSTYKM_vWQ@mail.gmail.com
In Reply to: Re: [gentoo-user] BOINC on a hardened system? by Peter Humphrey
1 By default, BOINC daemon is started by root and supposedly drops
2 permissions after a bit. However, the CERNVM VirtualBox application
3 cannot run as root, so they recommend running BOINC from a user
4 account that has virtualbox permissions; VirtualBox, on the other
5 hand, will not run as root for security reasons.
6
7 I got around this by making BOINC as "user" and moving its $HOME to
8 /home/boinc/ and I don't think I had to change anything (except the
9 /etc/conf.d/boinc file.) I am not using any hardening in the kernel,
10 so that may complicate things.
11
12 I currently run some 11 projects, including SETI, CERN, Einstein, and
13 World Community Grid. Everything works fine for me.
14
15 --
16 G.Wolfe Woodbury
17 redwolfe@×××××.com

Replies

Subject Author
Re: [gentoo-user] BOINC on a hardened system? Peter Humphrey <peter@××××××××××××.uk>