From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([208.92.234.80] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1QJYHA-0006Y0-33 for garchives@archives.gentoo.org; Mon, 09 May 2011 21:46:00 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 031921C00F; Mon, 9 May 2011 21:45:51 +0000 (UTC) Received: from smtp.gentoo.org (smtp.gentoo.org [140.211.166.183]) by pigeon.gentoo.org (Postfix) with ESMTP id C386B1C00F for ; Mon, 9 May 2011 21:45:50 +0000 (UTC) Received: from pelican.gentoo.org (unknown [66.219.59.40]) (using TLSv1 with cipher ADH-CAMELLIA256-SHA (256/256 bits)) (No client certificate requested) by smtp.gentoo.org (Postfix) with ESMTPS id 7C5A71B4045 for ; Mon, 9 May 2011 21:45:50 +0000 (UTC) Received: from localhost.localdomain (localhost [127.0.0.1]) by pelican.gentoo.org (Postfix) with ESMTP id 9BB6E80504 for ; Mon, 9 May 2011 21:45:49 +0000 (UTC) From: "Francisco Blas Izquierdo Riera" To: gentoo-commits@lists.gentoo.org Content-type: text/plain; charset=UTF-8 Reply-To: gentoo-dev@lists.gentoo.org, "Francisco Blas Izquierdo Riera" Message-ID: Subject: [gentoo-commits] proj/hardened-docs:master commit in: xml/ X-VCS-Repository: proj/hardened-docs X-VCS-Files: xml/grsecurity.xml X-VCS-Directories: xml/ X-VCS-Committer: klondike X-VCS-Committer-Name: Francisco Blas Izquierdo Riera X-VCS-Revision: e2383632c32d16e68e8baa0a29c5ab13ff303348 Date: Mon, 9 May 2011 21:45:49 +0000 (UTC) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-commits@lists.gentoo.org Content-Transfer-Encoding: quoted-printable X-Archives-Salt: X-Archives-Hash: 10860daf3b5d25ce3f1ac18d616dd5a6 commit: e2383632c32d16e68e8baa0a29c5ab13ff303348 Author: klondike xiscosoft es> AuthorDate: Mon May 9 21:46:03 2011 +0000 Commit: Francisco Blas Izquierdo Riera xiscosoft = es> CommitDate: Mon May 9 21:46:03 2011 +0000 URL: http://git.overlays.gentoo.org/gitweb/?p=3Dproj/hardened-docs= .git;a=3Dcommit;h=3De2383632 Adding a comment to disable learning mode prior to converting rules. Than= ks to Peter Harmsen --- xml/grsecurity.xml | 5 +++++ 1 files changed, 5 insertions(+), 0 deletions(-) diff --git a/xml/grsecurity.xml b/xml/grsecurity.xml index 4517f10..12648e5 100644 --- a/xml/grsecurity.xml +++ b/xml/grsecurity.xml @@ -468,6 +468,11 @@ let gradm process them and propose roles unde= r # gradm -F -L /etc/grsec/learning.log -O /etc/grsec/learning.roles =20 + +You will need to disable the RBAC learning mode before doing this. You c= an use +gradm -D for this. + +

Audit the /etc/grsec/learning.roles and save it as /etc/grsec/policy (mode 0600) when you are finished.