1 |
On Jan 15, 2012 10:33 PM, "Michael Orlitzky" <michael@××××××××.com> wrote: |
2 |
> |
3 |
> On 01/15/2012 08:36 AM, Tanstaafl wrote: |
4 |
>> |
5 |
>> |
6 |
>>> Virtualization is iffy if you're not careful which options you enable in |
7 |
>>> the kernel. |
8 |
>> |
9 |
>> |
10 |
>> I've been meaning to as a similar (but reverse) question - which I'll do |
11 |
>> in a separate thread later, but... |
12 |
>> |
13 |
>> Your reference to 'virtualizationis iffy' above... do you mean if you |
14 |
>> are going to run VMs on a hardened HOST? Or run a hardened machine as a |
15 |
>> VM? I had a problem trying to switch my Linode VM to the hardened |
16 |
>> profile, and ended up giving up on it... |
17 |
>> |
18 |
> |
19 |
> I was talking about a hardened host. Fortunately, newer kernels will have |
20 |
a preset "virtualization" profile that you can select to set only the safe |
21 |
options. See this thread for the announcement: |
22 |
> |
23 |
> |
24 |
http://archives.gentoo.org/gentoo-hardened/msg_4bfe02921ffff3c94d7ee59cdf8f3f38.xml |
25 |
> |
26 |
> I personally have never run a hardened guest, but in that post he alludes |
27 |
to the fact there may also be issues there, "...but in some |
28 |
> cases applies even for the guest." |
29 |
> |
30 |
> In either case, you would want to stick to the stable kernels, since new |
31 |
problems do crop up occasionally as new features are introduced. |
32 |
> |
33 |
|
34 |
I have been running hardened unstable kernels as guests on top of VMware |
35 |
vSphere and XenServer without any problems. |
36 |
|
37 |
Except for that one time where something went horribly wrong, rendering |
38 |
*everything* unusable. But that kernel was withdrawn and replaced with a |
39 |
new revision within 24 hours. |
40 |
|
41 |
Of course, YMMV. |
42 |
|
43 |
Rgds, |