public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-user]  Simplified apache2
@ 2006-09-12 13:40 James
  2006-09-12 15:08 ` Michael Crute
  0 siblings, 1 reply; 20+ messages in thread
From: James @ 2006-09-12 13:40 UTC (permalink / raw
  To: gentoo-user

Hello,

I  used 2006.1 livecd to install a pII machine. It's going
to becomme a (minimalistic) apache2 server. I just let the 
installation
set the  flags for the install  so I have these flags currently:

CURRENT
USE=" X alsa arts avi berkdb bitmap-fonts cairo cdr cli crypt
 cups dbus dlloader
dri dvd dvdr eds elibc_glibc emboss encode esd fam firefox 
fortran gdbm gif
gnome gpm gstreamer gtk hal input_devices_evdev 
input_devices_keyboard
input_devices_mouse ipv6 isdnlog jpeg kde kernel_linux 
ldap libg++ mad mikmod
mp3 mpeg ncurses nls nptl nptlonly ogg opengl oss pam pcre
 pdflib perl  png ppds
pppd python qt3 qt4 quicktime readline reflection sdl session 
spell spl  ssl tcpd
truetype truetype-fonts type1-fonts udev unicode 
userland_GNU vorbis win32codecs
x86 xml xorg xv zlib apache2  "


Some of these flag look questionable, such as the one with 
underscores (kernel_linux userland_GNU) as I only found 
information on them, where they are describe as 'undocumented
 use flags'. What's up with these flags?

Where do I look to discern the minimal list of (necessary) system 
flags that 
must be kept?  (I want to avoid negating any flags that are critical).


These are my proposed list of flags:

PROPOSED
 USE=" berkdb bitmap-fonts dbus hal jpeg ldap mp3 mpeg ncurses 
nls nptl nptlonly
ogg pam pcre pdflib perl png python quicktime readline sdl ssl 
tcpd truetype
truetype-fonts type1-fonts udev unicode  vorbis win32codecs  xml 
xv zlib apache2 "

So can I just use this list, or do I have to incluce a -{flag} for each one?

IS there simmpler syntax to globally remove unwanted flags [-*], but, not any
critical system flags? (Is this the same as just leaving the flag out
of the USE param. setting in make.conf?

Are there default system flag settings that I can safely remove?
Where is the list and how do I know which ones can be removed or negated?

My (limited) understanding of flags are that the highest priority are
those set in /etc/portage/package.use, then /etc/make.conf then
the system default flags which may be located in several locations.
Is there any docs or listing of all of these location and details
on precedence?


James

-- 
gentoo-user@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 20+ messages in thread
* Re: [gentoo-user]  Re: Simplified apache2
@ 2006-09-14  2:51 bridavis
  0 siblings, 0 replies; 20+ messages in thread
From: bridavis @ 2006-09-14  2:51 UTC (permalink / raw
  To: gentoo-user

[-- Attachment #1: Type: text/plain, Size: 1302 bytes --]

Thanks James!

-------------- Original message -------------- 
From: James <wireless@tampabay.rr.com> 

> Brian Davis comcast.net> writes: 
> 
> 
> > Can one covert a non-hardended machine to use the hardended-profile, or 
> > do you have to start from scratch? 
> 
> 
> Hello Brian, 
> 
> The short answer is YES. The correct answer is you have to 
> read quite a lot (I'm in the middle of that) and decide 
> which 'path/technology' you want to follow. Here's docs 
> you should start looking at: 
> 
> http://www.gentoo.org/proj/en/hardened/primer.xml 
> http://www.gentoo.org/proj/en/hardened/ 
> 
> I choose 'SElinux' as the path to follow for me 
> that makes most sense. Since the NSA was the prime 
> motivator, it's an easy path to convince my clients 
> to follow. Although SElinux is not a complete 
> solution, other complementary software combined with 
> SElinux does provide for a complete (security) solution, 
> almost..... 
> 
> 
> http://www.gentoo.org/proj/en/hardened/selinux/ 
> http://www.gentoo.org/proj/en/hardened/selinux/selinux-handbook.xml 
> http://www.gentoo.org/proj/en/hardened/selinux/selinux-handbook.xml?part=2 
> 
> hth, 
> http://www.gentoo.org/proj/en/hardened/selinux/selinux-handbook.xml?part=2 
> James 
> 
> 
> 
> -- 
> gentoo-user@gentoo.org mailing list 
> 

[-- Attachment #2: Type: text/html, Size: 1733 bytes --]

^ permalink raw reply	[flat|nested] 20+ messages in thread

end of thread, other threads:[~2006-09-15  0:22 UTC | newest]

Thread overview: 20+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-09-12 13:40 [gentoo-user] Simplified apache2 James
2006-09-12 15:08 ` Michael Crute
2006-09-12 15:36   ` [gentoo-user] " James
2006-09-12 23:27   ` [gentoo-user] " Ryan Tandy
2006-09-13 12:36     ` [gentoo-user] " James
2006-09-13 13:20       ` Rumen Yotov
2006-09-14 17:05         ` Brian Davis
2006-09-14 21:49           ` Brian Davis
2006-09-13 13:50       ` Michael Crute
2006-09-13 17:01       ` Bo Ørsted Andresen
2006-09-13 17:52         ` Stefan G. Weichinger
2006-09-13 18:08         ` Neil Bothwick
2006-09-13 19:13         ` Daniel da Veiga
2006-09-13 21:11           ` Harm Geerts
2006-09-13  5:07   ` [gentoo-user] " Michael Stewart (vericgar)
2006-09-13 13:45     ` Michael Crute
2006-09-15  0:17       ` Michael Stewart (vericgar)
2006-09-13 18:17   ` Brian Davis
2006-09-14  2:41     ` [gentoo-user] " James
  -- strict thread matches above, loose matches on Subject: below --
2006-09-14  2:51 bridavis

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox