[gentoo-hardened] Tips for upgrading to the current stable gentoo hardened?

2011-06-15 Thread Kārlis Repsons
Hi all, I've got a machine, which hasn't been upgraded for some 2 years or less. It has GCC-4.3.4 and now I tried to upgrade to 4.5.2, but something failed. So I'm here to ask for the right sequence of upgrades and other actions before it's too late... These actions done already: 1. updated bi

Re: [gentoo-hardened] Tips for upgrading to the current stable gentoo hardened?

2011-06-15 Thread Jean-François Maeyhieux
Hi ! another "hardcore" solution could be to create a chroot fresh installation whithin you import your system's preferences: - Create directory - Untar last hardened stage 3 - Copy your /etc in the chroot - Copy your world file in the chroot - Copy any kind of data or local aplication to your

[gentoo-hardened] SELinux policy for nginx, or include in apache?

2011-06-15 Thread Sven Vermeulen
Hi folks, As per bug #368795 [1] we have an open request to include a SELinux policy module for the nginx webserver. However, while working on this, I remembered a small discussion that upstream had about the same matter [2]. It boils down to the question: do we support nginx within the existing d

Re: [gentoo-hardened] SELinux policy for nginx, or include in apache?

2011-06-15 Thread Francisco Blas Izquierdo Riera (klondike)
El 15/06/11 19:45, Sven Vermeulen escribió: > Or do we see if we can deviate from upstream here and start our own path (in > my opinion, we can't as long as we do not have a critical developer mass - > in numbers, not in kilogram). Hey, I'm not that fat :P signature.asc Description: OpenPGP digi

Re: [gentoo-hardened] SELinux policy for nginx, or include in apache?

2011-06-15 Thread Anthony G. Basile
On 06/15/2011 01:45 PM, Sven Vermeulen wrote: > So... ideas? Do we want to "keep it simple" and update the apache policy to > support nginx? Or do we want to stay "least privilege" and have dedicated > rules for applications? > I'm only slowly coming around to policy development, but from my sel

Re: [gentoo-hardened] SELinux policy for nginx, or include in apache?

2011-06-15 Thread Chris Richards
On Wed, 2011-06-15 at 20:40 -0400, Anthony G. Basile wrote: > On 06/15/2011 01:45 PM, Sven Vermeulen wrote: > > > So... ideas? Do we want to "keep it simple" and update the apache policy to > > support nginx? Or do we want to stay "least privilege" and have dedicated > > rules for applications?