public inbox for gentoo-hardened@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-hardened] apparmor to be supported?
@ 2006-01-31 12:08 Marcel Meyer
  2006-01-31 14:15 ` Ned Ludd
  0 siblings, 1 reply; 2+ messages in thread
From: Marcel Meyer @ 2006-01-31 12:08 UTC (permalink / raw
  To: gentoo-hardened

Hello,

I haven't found anything about apparmor inside the archives.

Has anybody here some experience with it? What are it's advantages or 
disadvantages compared to selinux,rsbac/grsecurity etc.?

Will it also be included into the hardened project?

Thanks,
Marcel


PS: I'd like to restrict many things on a program base (so not only allowing 
port 80 outgoing for everything but only for firefox and portage f.ex.). 
But since I'm not in a hurry and it is only for the desktop I'd like to 
habe a look into several alternatives and would prefer to choose the modest 
one finally ;-)

-- 
Marcel Meyer
| Netzwerk- und Rechnerorganisation
| Fachschaft Mathematik/Physik/Informatik
| Technische Universität München

-- 
gentoo-hardened@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [gentoo-hardened] apparmor to be supported?
  2006-01-31 12:08 [gentoo-hardened] apparmor to be supported? Marcel Meyer
@ 2006-01-31 14:15 ` Ned Ludd
  0 siblings, 0 replies; 2+ messages in thread
From: Ned Ludd @ 2006-01-31 14:15 UTC (permalink / raw
  To: gentoo-hardened

On Tue, 2006-01-31 at 13:08 +0100, Marcel Meyer wrote:
> Hello,
> 
> I haven't found anything about apparmor inside the archives.
> 
> Has anybody here some experience with it? What are it's advantages or 
> disadvantages compared to selinux,rsbac/grsecurity etc.?
> 
> Will it also be included into the hardened project?

probably not. We already have 3 MAC systems around. 

> 
> Thanks,
> Marcel
> 
> 
> PS: I'd like to restrict many things on a program base (so not only allowing 
> port 80 outgoing for everything but only for firefox and portage f.ex.). 
> But since I'm not in a hurry and it is only for the desktop I'd like to 
> habe a look into several alternatives and would prefer to choose the modest 
> one finally ;-)
> 
> -- 
> Marcel Meyer
> | Netzwerk- und Rechnerorganisation
> | Fachschaft Mathematik/Physik/Informatik
> | Technische Universität München
> 
-- 
Ned Ludd <solar@gentoo.org>
Gentoo Linux

-- 
gentoo-hardened@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2006-01-31 14:17 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-01-31 12:08 [gentoo-hardened] apparmor to be supported? Marcel Meyer
2006-01-31 14:15 ` Ned Ludd

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox