1 |
On 01/15/2012 08:36 AM, Tanstaafl wrote: |
2 |
> |
3 |
>> Virtualization is iffy if you're not careful which options you enable in |
4 |
>> the kernel. |
5 |
> |
6 |
> I've been meaning to as a similar (but reverse) question - which I'll do |
7 |
> in a separate thread later, but... |
8 |
> |
9 |
> Your reference to 'virtualizationis iffy' above... do you mean if you |
10 |
> are going to run VMs on a hardened HOST? Or run a hardened machine as a |
11 |
> VM? I had a problem trying to switch my Linode VM to the hardened |
12 |
> profile, and ended up giving up on it... |
13 |
> |
14 |
|
15 |
I was talking about a hardened host. Fortunately, newer kernels will |
16 |
have a preset "virtualization" profile that you can select to set only |
17 |
the safe options. See this thread for the announcement: |
18 |
|
19 |
http://archives.gentoo.org/gentoo-hardened/msg_4bfe02921ffff3c94d7ee59cdf8f3f38.xml |
20 |
|
21 |
I personally have never run a hardened guest, but in that post he |
22 |
alludes to the fact there may also be issues there, "...but in some |
23 |
cases applies even for the guest." |
24 |
|
25 |
In either case, you would want to stick to the stable kernels, since new |
26 |
problems do crop up occasionally as new features are introduced. |