Gentoo Archives: gentoo-user

From: Francesco Talamona <francesco.talamona@××××.eu>
To: gentoo-user@l.g.o
Subject: Re: /boot or not /boot (was Re: [gentoo-user] can't stop the panic on eeepc)
Date: Sun, 10 May 2009 06:48:25
Message-Id: 200905100848.22226.francesco.talamona@know.eu
In Reply to: Re: /boot or not /boot (was Re: [gentoo-user] can't stop the panic on eeepc) by Dale
1 On Saturday 09 May 2009, Dale wrote:
2 > I was talking about with just a plain file system.  I read in a
3 > install guide somewhere when I was installing ages ago that having
4 > /boot on a separate partition, and not always mounted, was a good
5 > security practice.  That way no one could alter the kernel since it
6 > was not mounted.
7 >
8 > I do agree that if a person was on the system and able to get root
9 > access, they could them mount the /boot partition as well.  I never
10 > was really sure why this was thought to work.  I used a separate
11 > /boot because for a while I was dual booting Mandrake and Gentoo.
12 >  Old habit now I guess.
13
14 It's a suggestion for security against user errors; I'm pretty sure it
15 was there long before genkernel came out, when there
16 wasn't "automation" in kernel building.
17
18 Furthermore you can use a non journalled filesystem for /boot.
19
20 Ciao
21 Francesco
22
23 --
24 Linux Version 2.6.29-gentoo-r3, Compiled #2 SMP PREEMPT Sat May 9
25 18:15:29 CEST 2009
26 Two 1GHz AMD Athlon 64 Processors, 4GB RAM, 4018.42 Bogomips Total
27 aemaeth

Replies