Re: [gentoo-hardened] New Kconfig structure in hardened-sources-3.4.4-r1

2012-07-01 Thread Anthony G. Basile
On 07/01/2012 04:04 PM, Anthony G. Basile wrote: Hi everyone, 2. I've tried to keep the Gentoo GIDs where possible. There is one bug that I've noticed, which I'm passing to upstream. Toggling "Invert GID option" under TPE does not toggle between our trusted (GID=10) and our untrusted (GID=100

[gentoo-hardened] New Kconfig structure in hardened-sources-3.4.4-r1

2012-07-01 Thread Anthony G. Basile
Hi everyone, Upstream has change the structure of the configuration menu for grsec/pax. The new Kconfig is in hardened-sources-3.4.4-r1 which I have just added to the tree. I want to alert the list so people are not surprised upon upgrade. Here's roughly what has changed: 0. The Grsecurit

Re: [gentoo-hardened] SELinux Gentoo/Hardened amd64 VM

2012-07-01 Thread Sven Vermeulen
On Sun, Jul 01, 2012 at 10:56:31AM -0500, Matthew Thode wrote: > What is the full command line you used for this? (qemu-system-x86_64...) The one I use is the following: qemu-system-x86_64 --enable-kvm -gdb tcp::1239 -vnc 127.0.0.1:5 -net nic,model=virtio,macaddr=00:11:22:33:44:b1,vlan=0 -net vde

Re: [gentoo-hardened] SELinux Gentoo/Hardened amd64 VM

2012-07-01 Thread Matthew Thode
On 07/01/2012 09:44 AM, Sven Vermeulen wrote: > Hi guys, > > I'm working on having SELinux-enabled, Gentoo Hardened VMs available for > people to test things with. If succesfull, I'd also like to see if I can > create some sort of DIY-course on SELinux based on these images (i.e. > documentation b

[gentoo-hardened] SELinux Gentoo/Hardened amd64 VM

2012-07-01 Thread Sven Vermeulen
Hi guys, I'm working on having SELinux-enabled, Gentoo Hardened VMs available for people to test things with. If succesfull, I'd also like to see if I can create some sort of DIY-course on SELinux based on these images (i.e. documentation based on these VMs with educational questions and tasks for