public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
From: Joachim Blaabjerg <styx@SuxOS.org>
To: gentoo-dev@gentoo.org
Subject: Re: [gentoo-dev] Secure Gentoo - What do you think?
Date: Tue, 8 Jan 2002 19:18:15 +0100	[thread overview]
Message-ID: <20020108191815.75220efd.styx@SuxOS.org> (raw)
In-Reply-To: <1010503635.25864.0.camel@red.ces.clemson.edu>

On 08 Jan 2002 10:27:15 -0500
Grant Goodyear <goodyea@clemson.edu> wrote:
> 
> Gads, I hope not!  If you do need to modify all of the ebuilds, then we
> haven't done our jobs very well.  

There are a few problems that hopefully can be avoided easily, such as post
installation routines. I was planning on using a modularized script to update
the LIDS ACLs, and letting every new program add ACLs for itself in one
directory (one file for each program) upon installation. The problem (if one can
call it that) is that I've recently decided to make a deny-all type of LIDS
configuration, so every program that intends to do anything in particular will
need specialized LIDS ACLs... So unless there is a special way of doing this, I
think I'll have to modify a couple of .ebuild files... :-/ Luckily, I don't
intend to include all the programs you guys have made .ebuild files for, such as
X, Gnome, KDE, and other applications that are strictly unneccessary (and maybe
even a security risk) on a dedicated server.

> As for where to start, I assume you've installed Gentoo once or twice to get a
> good feel for how it works? 

Hopefully, I'll get an ADSL connection tomorrow (after waiting for a couple of
years...), so I can install Gentoo for the first time. I downloaded the .iso,
but downloading tens or hundreds of megabytes of source isn't really feasible
when you're connected to the 'net with a 56k modem ;)

> Then I would start on building a minimal SuxOS system.  You'll
> presumably need to modify the bootstrap.sh script to compile glibc
> with formatguard, create a SuxOS kernel ebuild that includes all of the
> necessary patches, and make a /usr/portage/profiles/SuxOS/packages file
> tailored to SuxOS needs.  Come play on #gentoo on irc.openprojects.net;
> we'll be happy to help!

#gentoo, here I come! ;)

BTW, have you guys got any ideas for a name?

Regards

-- 
Joachim Blaabjerg
styx@SuxOS.org
www.SuxOS.org


  reply	other threads:[~2002-01-08 18:17 UTC|newest]

Thread overview: 32+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-01-07 16:13 [gentoo-dev] Secure Gentoo - What do you think? Joachim Blaabjerg
2002-01-07 16:29 ` Daniel Robbins
2002-01-07 16:31 ` Grant Goodyear
2002-01-07 16:37 ` Geert Bevin
2002-01-07 16:43 ` Tod M. Neidt
2002-01-08  0:33 ` Jano Lukac
2002-01-08  7:22   ` AW: " Sebastian Werner
2002-01-08 10:51 ` Mikael Hallendal
2002-01-08 11:14   ` AW: " Sebastian Werner
2002-01-08 13:27   ` Joachim Blaabjerg
2002-01-08 15:27     ` Grant Goodyear
2002-01-08 18:18       ` Joachim Blaabjerg [this message]
2002-01-08 18:42         ` Tod M. Neidt
2002-01-08 15:54     ` Damon M. Conway
2002-01-08 16:00       ` Mikael Hallendal
2002-01-08 17:10         ` Damon M. Conway
2002-01-08 17:15           ` Mikael Hallendal
2002-01-08 18:11             ` Damon M. Conway
2002-01-08 23:35               ` Mikael Hallendal
2002-01-10 11:24           ` Karl Trygve Kalleberg
2002-01-10 11:56             ` [gentoo-dev] Secure Gentoo - OO-ebuilds Einar Karttunen
2002-01-10 15:23             ` [gentoo-dev] Secure Gentoo - What do you think? Dan Armak
2002-01-10 13:51 ` Joachim Blaabjerg
2002-01-10 14:40   ` Mikael Hallendal
2002-01-10 15:00     ` Joachim Blaabjerg
2002-01-10 15:27       ` AW: " Sebastian Werner
2002-01-10 17:09       ` Joachim Blaabjerg
2002-01-10 18:48         ` Daniel Robbins
2002-01-11 19:07         ` Sebastian Werner
2002-01-11 20:07           ` Joachim Blaabjerg
2002-01-10 18:28       ` Martin Schlemmer
2002-01-10 18:49   ` Grant Goodyear

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20020108191815.75220efd.styx@SuxOS.org \
    --to=styx@suxos.org \
    --cc=gentoo-dev@gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox