Re: [gentoo-hardened] Suggestion for kernel tree: Pax + linux-vserver

2010-11-03 Thread klondike
El 04/11/10 00:26, Francesco R escribió: > 2010/11/3 Ed W mailto:li...@wildgooses.com>> > > Just to run an idea up the flagpole... > > I have had good success with a slightly orthogonal approach to > securing my servers. I run a hardened gentoo install, but with > linux-vservers fo

Re: [gentoo-hardened] Suggestion for kernel tree: Pax + linux-vserver

2010-11-03 Thread Francesco R
2010/11/3 Ed W > Just to run an idea up the flagpole... > > I have had good success with a slightly orthogonal approach to securing my > servers. I run a hardened gentoo install, but with linux-vservers for the > guests and additionally pax kernel patches. > > The motivation is that Pax has miti

[gentoo-hardened] Suggestion for kernel tree: Pax + linux-vserver

2010-11-03 Thread Ed W
Just to run an idea up the flagpole... I have had good success with a slightly orthogonal approach to securing my servers. I run a hardened gentoo install, but with linux-vservers for the guests and additionally pax kernel patches. The motivation is that Pax has mitigated a reasonable propor

Re: [gentoo-hardened] Re: [gentoo-security] #342619 RESOLVED WONTFIX

2010-11-03 Thread Tóth Attila
It is a good candidate to become a conditional patch for hardened. Dw. -- dr Tóth Attila, Radiológus, 06-20-825-8057, 06-30-5962-962 Attila Toth MD, Radiologist, +36-20-825-8057, +36-30-5962-962 2010.November 3.(Sze) 19:09 időpontban Ed W ezt írta: > On 28/10/2010 02:14, Pavel Labushev wrote: >>

Re: [gentoo-hardened] Re: [gentoo-security] #342619 RESOLVED WONTFIX

2010-11-03 Thread Ed W
On 28/10/2010 02:14, Pavel Labushev wrote: eruption or something else. Now collection is expanded to patches that will not be mainstreamed :> This is GOOD PRACTICE :). Thinking about Another distros do include patches for glibc not accepted by mainstream. In this particular case the patch is p