Gentoo Archives: gentoo-user

From: Pandu Poluan <pandu@××××××.info>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Is it possible to move from hardened profile?
Date: Sun, 15 Jan 2012 17:20:37
Message-Id: CAA2qdGXBdjvtz94WRNN_Zrninupxf7x4y0rHt=GxXV4dEOErEw@mail.gmail.com
In Reply to: Re: [gentoo-user] Re: Is it possible to move from hardened profile? by Michael Orlitzky
1 On Jan 15, 2012 10:33 PM, "Michael Orlitzky" <michael@××××××××.com> wrote:
2 >
3 > On 01/15/2012 08:36 AM, Tanstaafl wrote:
4 >>
5 >>
6 >>> Virtualization is iffy if you're not careful which options you enable in
7 >>> the kernel.
8 >>
9 >>
10 >> I've been meaning to as a similar (but reverse) question - which I'll do
11 >> in a separate thread later, but...
12 >>
13 >> Your reference to 'virtualizationis iffy' above... do you mean if you
14 >> are going to run VMs on a hardened HOST? Or run a hardened machine as a
15 >> VM? I had a problem trying to switch my Linode VM to the hardened
16 >> profile, and ended up giving up on it...
17 >>
18 >
19 > I was talking about a hardened host. Fortunately, newer kernels will have
20 a preset "virtualization" profile that you can select to set only the safe
21 options. See this thread for the announcement:
22 >
23 >
24 http://archives.gentoo.org/gentoo-hardened/msg_4bfe02921ffff3c94d7ee59cdf8f3f38.xml
25 >
26 > I personally have never run a hardened guest, but in that post he alludes
27 to the fact there may also be issues there, "...but in some
28 > cases applies even for the guest."
29 >
30 > In either case, you would want to stick to the stable kernels, since new
31 problems do crop up occasionally as new features are introduced.
32 >
33
34 I have been running hardened unstable kernels as guests on top of VMware
35 vSphere and XenServer without any problems.
36
37 Except for that one time where something went horribly wrong, rendering
38 *everything* unusable. But that kernel was withdrawn and replaced with a
39 new revision within 24 hours.
40
41 Of course, YMMV.
42
43 Rgds,