1 |
On 09/06/2015 04:15 PM, walt wrote: |
2 |
> https://wiki.gentoo.org/wiki/Hardened_Gentoo |
3 |
> |
4 |
> That wiki page is very seductive. It makes me want to drop everything |
5 |
> and select a hardened profile and re-emerge everything from scratch. |
6 |
> |
7 |
> But I have a feeling I'd soon be in big trouble if I did. Is this |
8 |
> something that only gentoo devs should be messing with, or is this |
9 |
> a project that a typical gentoo end-user might hope to accomplish |
10 |
> without frequent suicidal thoughts? |
11 |
|
12 |
It depends on how many hardening features you want to enable. It's a lot |
13 |
easier than it used to be because there's a kernel config thingy that |
14 |
lets you pick safe options without understanding all the details. You |
15 |
can get a lot of protection for very little risk by enabling pax/grsec |
16 |
and checking a few boxes in the hardened kernel config. |
17 |
|
18 |
Just beware that there are kernel options that will clobber things like |
19 |
cpupower and others that will slow down specific programs like clamav |
20 |
with JIT. Anyway, we're all here because we like to tinker with things |
21 |
until they're broken, right? Give it a try and be sure to read the |
22 |
kernel help pages carefully and have fun. You can always switch back to |
23 |
a non-hardened kernel and everything will go back to normal. |