public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-user] How to harden a system
@ 2017-12-23 14:09 Peter Humphrey
  2017-12-23 17:46 ` Michael Orlitzky
                   ` (2 more replies)
  0 siblings, 3 replies; 15+ messages in thread
From: Peter Humphrey @ 2017-12-23 14:09 UTC (permalink / raw
  To: gentoo-user

Hello list,

Now that grsecurity is off-limits, I'm left wondering how to go about 
hardening a no-multilib box that will be exposed to the Big Bad World.

To start with, it's not obvious which profile to use:

$ eselect profile list | grep no-multi | grep hardened
  [23]  default/linux/amd64/17.0/no-multilib/hardened
  [24]  default/linux/amd64/17.0/no-multilib/hardened/selinux
  [29]  hardened/linux/amd64/no-multilib
  [30]  hardened/linux/amd64/no-multilib/selinux

The wiki is also now out of date; it still talks about grsecurity, and there 
are too many overlapping guides.

Until that's sorted out, would the panel like to offer some guidance?

-- 
Regards,
Peter.



^ permalink raw reply	[flat|nested] 15+ messages in thread

end of thread, other threads:[~2017-12-26 18:33 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-12-23 14:09 [gentoo-user] How to harden a system Peter Humphrey
2017-12-23 17:46 ` Michael Orlitzky
2017-12-23 18:09   ` Peter Humphrey
2017-12-24  3:20 ` Adam Carter
2017-12-24  9:43   ` Adam Carter
2017-12-24 18:37     ` Grant Taylor
2017-12-25 15:00   ` Michael Orlitzky
2017-12-24 19:44 ` Taiidan
2017-12-25  6:55   ` R0b0t1
2017-12-25  6:56     ` R0b0t1
2017-12-25 15:33       ` Frank Steinmetzger
2017-12-25 18:55         ` Stroller
2017-12-25 23:33   ` [gentoo-user] " Ian Zimmerman
2017-12-25 23:41     ` Grant Taylor
2017-12-26 18:33     ` Taiidan

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox