public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
From: Tully Gray <tully.gray@outlook.com>
To: "gentoo-user@lists.gentoo.org" <gentoo-user@lists.gentoo.org>
Subject: RE: [gentoo-user] Is Hardened profile and SELinux support active?
Date: Wed, 8 Apr 2020 16:59:32 +0000	[thread overview]
Message-ID: <SYBPR01MB51775A5BB842BF010D41B1DF87C00@SYBPR01MB5177.ausprd01.prod.outlook.com> (raw)
In-Reply-To: <2982192.5fSG56mABF@dell_xps>

>> Hi everyone, 
>> 
>> I am very new to Gentoo and I am currently migrating from Arch. 
>> Gentoo attracts me with a freedom of system configuration and with multiple 
>> supported architectures. 
>> 
>> I was attracted by Hardened profile described at [1][2][3] 
>> But reading [1] I also got confused because it looks like it is no longer 
>> maintained. 
>> 
>> So the question is it just outdated wiki page? Is anyone using Hardened 
>> profile? Is it maintained? In Archlinux SELinux is not supported officially 
>> so this is why I am looking around. 
>> 
>> Thanks/ 
>> 
>> [1] https://wiki.gentoo.org/wiki/Project:Hardened[1] 
>> [2] https://wiki.gentoo.org/wiki/Hardened/FAQ[2] 
>> [3] https://wiki.gentoo.org/wiki/Hardened_Gentoo[3] 

>I have never used a Hardened profile and have not followed up what happened 
>after the GRSecurity developer abandoned his code development.[1] 
>https://grsecurity.net/passing_the_baton 
>Someone else could comment on the future of Gentoo Hardened, but I am posting 
>this message having noticed your message may have not made it through to some 
>recipients (the dreaded DMARC caused a DKIM header failure again).

I have fairly recently (in the last six months) converted my Gentoo systems to
use SELinux.  The process was relatively painless and the quality of the
documentation was very good.  Already in this short period of time I have
updated all systems with a new SELinux policy.  Portage (Gentoo's package
manager) appears to handle policy updates quite well and the update took place
without any major problems.  The main dev responsible of SELinux on Gentoo is
approachable and knowledgeable.

I'd say that SELinux on Gentoo seems to be in rather good health!

Tully.


  reply	other threads:[~2020-04-08 16:59 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-04-07  4:40 [gentoo-user] Is Hardened profile and SELinux support active? Ihor Antonov
2020-04-08 11:54 ` Michael
2020-04-08 16:59   ` Tully Gray [this message]
2020-04-09 13:42 ` Nils Freydank

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=SYBPR01MB51775A5BB842BF010D41B1DF87C00@SYBPR01MB5177.ausprd01.prod.outlook.com \
    --to=tully.gray@outlook.com \
    --cc=gentoo-user@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox