Peter S. Mazinger wrote:
On Sun, 7 May 2006, Alex Efros wrote:
Hi!
On Sun, May 07, 2006 at 12:28:40AM -0400, Kevin wrote:
If I wanted all four of the Xen/SELinux/PaX/GRSecurity patch sets
incorporated into a kernel, any recommendations for doing this?
AFAIK hardened-sources already contain S
On Sun, 7 May 2006, Alex Efros wrote:
> Hi!
>
> On Sun, May 07, 2006 at 12:28:40AM -0400, Kevin wrote:
> > If I wanted all four of the Xen/SELinux/PaX/GRSecurity patch sets
> > incorporated into a kernel, any recommendations for doing this?
>
> AFAIK hardened-sources already contain SELinux+PaX+
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1
Kevin wrote:
> Chris PeBenito wrote:
>> On Sun, 2006-05-07 at 00:28 -0400, Kevin wrote:
>>> xen-sources (which patches the kernel for xen but not for
>>> SELinux/PaX/GRSecurity)
>>>
>>> or
>>>
>>> hardened-sources (which patches the kernel for SELinux/
Chris PeBenito wrote:
> On Sun, 2006-05-07 at 00:28 -0400, Kevin wrote:
>> xen-sources (which patches the kernel for xen but not for
>> SELinux/PaX/GRSecurity)
>>
>> or
>>
>> hardened-sources (which patches the kernel for SELinux/PaX/GRSecurity
>> but not for xen)
>
> Just so you know, SELinux is
On Sun, 2006-05-07 at 00:28 -0400, Kevin wrote:
> xen-sources (which patches the kernel for xen but not for
> SELinux/PaX/GRSecurity)
>
> or
>
> hardened-sources (which patches the kernel for SELinux/PaX/GRSecurity
> but not for xen)
Just so you know, SELinux is available in all 2.6 kernels, sin
> Has anyone done anything like this? Is it silly to even think that the
> hand-applied patches will apply without rejects?
I haven't tried myself, but I have read in a few spots that it can't be
done.
> Or should I be doing a strictly Xen kernel as the host kernel and if I
> want SELinux/PaX/GR
Hi!
On Sun, May 07, 2006 at 12:28:40AM -0400, Kevin wrote:
> If I wanted all four of the Xen/SELinux/PaX/GRSecurity patch sets
> incorporated into a kernel, any recommendations for doing this?
AFAIK hardened-sources already contain SELinux+PaX+GRSecurity.
--
WBR, Alex.
-
Hi Folks-
I've read a little discussion in the archive on this subject (such as
http://www.mail-archive.com/gentoo-hardened@lists.gentoo.org/msg00338.html)
but not much and not recently.
I've also read a little discussion in non-gentoo forums:
http://linux.slashdot.org/article.pl?sid=05/11/01/044