Re: Security features in Debian 8 (Jessie)
Javier Fernández-Sanguino Peña <[email protected]>
| Newsgroups | gmane.linux.debian.devel.www |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Apr 27, 2015 at 07:32:18PM +0200, [email protected] wrote: > You wrote that these hardening flags are individual for all packages. > So is it possible to see which packages have which build flags > enabled? (via the new package tracker or the package search). In https://wiki.debian.org/ReleaseGoals/SecurityHardeningBuildFlags you will find pointers to the list of packages have these features enabled. These are maintained by the team driving the process and they list those that are fixed, partially fixed and being workd on or checked: Packages of priority important or higher: http://anonscm.debian.org/viewvc/secure-testing/hardening/subgoal-important.txt?view=co Network-accesible daemons: http://anonscm.debian.org/viewvc/secure-testing/hardening/subgoal-daemons.txt?view=co Interpreters: http://anonscm.debian.org/viewvc/secure-testing/hardening/subgoal-interpreters.txt?view=co Packages with a DSA since 2006: http://anonscm.debian.org/viewvc/secure-testing/hardening/subgoal-dsa.txt?view=co You also have some statistics here: http://outflux.net/debian/hardening/ > It's not practicable to install each package and test it with a > script or look in the build file. No need to do that, the script used for the statistics uses a local mirror to obtain the information. > And for the kernel hardening: -fstack-protector and runtime memory > allocation validation are not exactly described in the > https://wiki.debian.org/Hardening [1] page. The Wiki just has references to these features. The description of those exact security features should be found elsewhere (in the Linux kernel documentation) > I'd like to express with the wiki page (the Security Features Matrix) > that it would be nice to see all information at one point. Probably it > would be good to include such a Matrix in the official documentation > or the release notes. I know that the Debian project is working > heavily on security, but the documentation of this process is not very > good. Yes, the documentation can be improved but, unfortunately, just "wishing" it to be done is not going to get it done. We are, after all, a volunteer organisation. People are working on a lot of things and some others can get, from time to time, neglected. Unfortunately, documentation is sometimes neglected. But I encourage you to help in the documentation, if you so desire, the process is open to anybody with a willingness to improve it. Best regards Javier
signature.asc
(application/pgp-signature, 811 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBVUK/PDg8os7RvajdAQiXNA/7B9fQB4dsieMxwltVQKoKO7RfpiAK3M7X clkFR0pNfv8y70Hn9jrf+aOAIgrslyP43CJIaPLvtJJYEJfp3AC3I7CSQAcCFj8x 72D1w1sO7X5jJb2Z8lOO5Tahf70uEsFn3UYooh7ISb3hyIpAIgLWQ+5BbsGB/nkS Boqo5PPB7wg/k9VMrhMrkNXm+Yag+wUN4QbVTE7tEgWm85VyaxK3X5RTNyma8e0+ IkWORA+XCTupe2fOz1Qa4+3Plnhgz4MXwDpAc+CO/YDnMeqI1LeYj7kMmIU3MWCB 3m3JJQ1gdPdP9XXGuk02XktaaryV0N0UEkPVfeyB4jPPESJPFu2UEFK0aPk3h4zJ xbXi34de6kRoUR6TnXhxldas6LWndj/e1FdpsxVOIozaiVAUuIK9M48dprPkmPAO /SXjT0ykyJgTg+wv3RLk3vSfOKbz3DozSuk1jSfkxui4BNIueyKnvUoHtZMu65s5 XcSr5NqFgOfJ41LOI74geIhASwpfPnRfAnt17+TUx/oji2rQYa/DOZ35I8dGILtL oCTvTNaan1kUBfz0o0yjBKx2XDgL7cWLBjR8FBD8QHRCkXYxKclvGzK4ajsz5xue iLSV2ucYl9Rfe4AZFec1YwAhLBQlAXlJ4UuGmuSphJx9mTUAZGW10d+JcUDkmB1h Odv3FyxnIBo= =O4Gd -----END PGP SIGNATURE-----