Hardening a Kernel post hardened-sources

Robert Sharp <selinux-/[email protected]> Wed, 28 Mar 2018 18:06:00 +0100
Newsgroups gmane.linux.gentoo.hardened
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--------------67473D1E3A85DBDC5899C833
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit

Hi,

I still have hardened-sources running on one PC and I keep trying to 
compile a replacement gentoo-sources with as much hardening as I can, 
but I haven't found anything to help me that actually works. There are 
some guides on the Internet but most of the them are quite old (still 
grsecurity) and some of them are really old (Kernel 2.2, for example).

I found the KSPP website and built a kernel using their suggested 
"paranoid" settings. It worked for a brief moment but then I think I 
upgraded gcc to 6.4 and it just panicked during boot causing a lot of 
pain to reverse out of.

Does anyone know of a good, post GRSecurity guide to reasonable security 
for the kernel? In the absence of anything else I will have to go back 
to the KSPP list and start removing stuff until I can get a stable kernel.

Thanks in advance,

Robert Sharp


--------------67473D1E3A85DBDC5899C833
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 7bit

<html>
  <head>

    <meta http-equiv="content-type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <p><font face="Arial">Hi,</font></p>
    <p><font face="Arial">I still have hardened-sources running on one
        PC and I keep trying to compile a replacement gentoo-sources
        with as much hardening as I can, but I haven't found anything to
        help me that actually works. There are some guides on the
        Internet but most of the them are quite old (still grsecurity)
        and some of them are really old (Kernel 2.2, for example). <br>
      </font></p>
    <p><font face="Arial">I found the KSPP website and built a kernel
        using their suggested "paranoid" settings. It worked for a brief
        moment but then I think I upgraded gcc to 6.4 and it just
        panicked during boot causing a lot of pain to reverse out of. <br>
      </font></p>
    <p><font face="Arial">Does anyone know of a good, post GRSecurity
        guide to reasonable security for the kernel? In the absence of
        anything else I will have to go back to the KSPP list and start
        removing stuff until I can get a stable kernel.</font></p>
    <p><font face="Arial">Thanks in advance,</font></p>
    <p><font face="Arial">Robert Sharp</font><br>
    </p>
  </body>
</html>

--------------67473D1E3A85DBDC5899C833--