Re: Hardening a Kernel post hardened-sources
Guillaume Ceccarelli <[email protected]> Thu, 29 Mar 2018 12:47:57 +0200
| Newsgroups | gmane.linux.gentoo.hardened |
|---|---|
| Message-ID | <[email protected]> |
--Apple-Mail-810EE19F-BC9C-40A1-B729-D3BE8C741122 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Hi all, I=E2=80=99ve been a grsecurity customer for a little over two years now, and= my use of it is as a small business, on Gentoo server installations. While I= can=E2=80=99t disclose the amount of money I=E2=80=99m paying publicly beca= use every deal is customized, I would encourage you to get in touch using th= e contact form on grsecurity.net and ask for a quote if you haven=E2=80=99t a= lready. You might just end up with an arrangement you can afford, and grsec is still= certainly worth having today. Not only for the feature set, but also for th= e constant looking over the mainline Linux kernel code, including fixing and= backporting more fixes than the regular kernel stable releases, and for kno= wledge / emails giving context to important kernel vulnerabilities when they= occur. Best, =E2=80=93 Guillaume Ceccarelli=20 >> On 28 Mar 2018, at 20:22, R0b0t1 <[email protected]> wrote: >>=20 >> On Wed, Mar 28, 2018 at 12:40 PM, Alex Efros <[email protected]> wro= te: >> Hi! >>=20 >>> On Wed, Mar 28, 2018 at 06:06:00PM +0100, Robert Sharp wrote: >>> Does anyone know of a good, post GRSecurity guide to reasonable security= >>> for the kernel? In the absence of anything else I will have to go back >>> to the KSPP list and start removing stuff until I can get a stable kerne= l. >>=20 >> I'm using https://github.com/minipli/linux-unofficial_grsec, but it lacks= >> Spectre and Meltdown mitigation at the moment (see issues). Still, I >> believe it's the best we can have now (better is probably paid GrSec, but= >> AFAIK it's impossible or too costly to buy it for home or small business)= . >=20 > Previous contributors have access to the code, but it doesn't seem > like there is any way to go that route anymore. >=20 --Apple-Mail-810EE19F-BC9C-40A1-B729-D3BE8C741122 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D= utf-8"></head><body dir=3D"auto"><div><span></span></div><div><div></div><di= v><span style=3D"background-color: rgba(255, 255, 255, 0);">Hi all,<br><br>I= =E2=80=99ve been a grsecurity customer for a little over two years now, and m= y use of it is as a small business, on Gentoo server installations. While I c= an=E2=80=99t disclose the amount of money I=E2=80=99m paying publicly becaus= e every deal is customized, I would encourage you to get in touch using the c= ontact form on <a href=3D"http://grsecurity.net/" dir=3D"ltr" x-apple-d= ata-detectors=3D"true" x-apple-data-detectors-type=3D"link" x-apple-data-det= ectors-result=3D"0">grsecurity.net</a> and ask for a quote if you haven= =E2=80=99t already.<br><br>You might just end up with an arrangement you can= afford, and grsec is still certainly worth having today. Not only for the f= eature set, but also for the constant looking over the mainline Linux kernel= code, including fixing and backporting more fixes than the regular kernel s= table releases, and for knowledge / emails giving context to important kerne= l vulnerabilities when they occur.<br><br><br>Best,<br><br>=E2=80=93 Guillau= me Ceccarelli </span></div><div><br>On 28 Mar 2018, at 20:22, R0b0t1 &l= t;<a href=3D"mailto:[email protected]">[email protected]</a>> wrote:<br><br= ></div><blockquote type=3D"cite"><div><span>On Wed, Mar 28, 2018 at 12:40 PM= , Alex Efros <<a href=3D"mailto:[email protected]">powerman@powerman= .name</a>> wrote:</span><br><blockquote type=3D"cite"><span>Hi!</span><br= ></blockquote><blockquote type=3D"cite"><span></span><br></blockquote><block= quote type=3D"cite"><span>On Wed, Mar 28, 2018 at 06:06:00PM +0100, Robert S= harp wrote:</span><br></blockquote><blockquote type=3D"cite"><blockquote typ= e=3D"cite"><span>Does anyone know of a good, post GRSecurity guide to reason= able security</span><br></blockquote></blockquote><blockquote type=3D"cite">= <blockquote type=3D"cite"><span>for the kernel? In the absence of anything e= lse I will have to go back</span><br></blockquote></blockquote><blockquote t= ype=3D"cite"><blockquote type=3D"cite"><span>to the KSPP list and start remo= ving stuff until I can get a stable kernel.</span><br></blockquote></blockqu= ote><blockquote type=3D"cite"><span></span><br></blockquote><blockquote type= =3D"cite"><span>I'm using <a href=3D"https://github.com/minipli/linux-unoffi= cial_grsec">https://github.com/minipli/linux-unofficial_grsec</a>, but it la= cks</span><br></blockquote><blockquote type=3D"cite"><span>Spectre and Meltd= own mitigation at the moment (see issues). Still, I</span><br></blockquote><= blockquote type=3D"cite"><span>believe it's the best we can have now (better= is probably paid GrSec, but</span><br></blockquote><blockquote type=3D"cite= "><span>AFAIK it's impossible or too costly to buy it for home or small busi= ness).</span><br></blockquote><blockquote type=3D"cite"><span></span><br></b= lockquote><span></span><br><span>Previous contributors have access to the co= de, but it doesn't seem</span><br><span>like there is any way to go that rou= te anymore.</span><br><span></span><br></div></blockquote></div></body></htm= l>= --Apple-Mail-810EE19F-BC9C-40A1-B729-D3BE8C741122--