Gentoo Archives: gentoo-user

From: Michael Orlitzky <michael@××××××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Is it possible to move from hardened profile?
Date: Sun, 15 Jan 2012 15:31:41
Message-Id: 4F12F10A.3090201@orlitzky.com
In Reply to: Re: [gentoo-user] Re: Is it possible to move from hardened profile? by Tanstaafl
1 On 01/15/2012 08:36 AM, Tanstaafl wrote:
2 >
3 >> Virtualization is iffy if you're not careful which options you enable in
4 >> the kernel.
5 >
6 > I've been meaning to as a similar (but reverse) question - which I'll do
7 > in a separate thread later, but...
8 >
9 > Your reference to 'virtualizationis iffy' above... do you mean if you
10 > are going to run VMs on a hardened HOST? Or run a hardened machine as a
11 > VM? I had a problem trying to switch my Linode VM to the hardened
12 > profile, and ended up giving up on it...
13 >
14
15 I was talking about a hardened host. Fortunately, newer kernels will
16 have a preset "virtualization" profile that you can select to set only
17 the safe options. See this thread for the announcement:
18
19 http://archives.gentoo.org/gentoo-hardened/msg_4bfe02921ffff3c94d7ee59cdf8f3f38.xml
20
21 I personally have never run a hardened guest, but in that post he
22 alludes to the fact there may also be issues there, "...but in some
23 cases applies even for the guest."
24
25 In either case, you would want to stick to the stable kernels, since new
26 problems do crop up occasionally as new features are introduced.

Replies

Subject Author
Re: [gentoo-user] Re: Is it possible to move from hardened profile? Pandu Poluan <pandu@××××××.info>