Re: Hardening a Kernel post hardened-sources

Guillaume Ceccarelli <[email protected]> Thu, 29 Mar 2018 12:47:57 +0200
Newsgroups gmane.linux.gentoo.hardened
Message-ID <[email protected]>
--Apple-Mail-810EE19F-BC9C-40A1-B729-D3BE8C741122
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hi all,

I=E2=80=99ve been a grsecurity customer for a little over two years now, and=
 my use of it is as a small business, on Gentoo server installations. While I=
 can=E2=80=99t disclose the amount of money I=E2=80=99m paying publicly beca=
use every deal is customized, I would encourage you to get in touch using th=
e contact form on grsecurity.net and ask for a quote if you haven=E2=80=99t a=
lready.

You might just end up with an arrangement you can afford, and grsec is still=
 certainly worth having today. Not only for the feature set, but also for th=
e constant looking over the mainline Linux kernel code, including fixing and=
 backporting more fixes than the regular kernel stable releases, and for kno=
wledge / emails giving context to important kernel vulnerabilities when they=
 occur.


Best,

=E2=80=93 Guillaume Ceccarelli=20

>> On 28 Mar 2018, at 20:22, R0b0t1 <[email protected]> wrote:
>>=20
>> On Wed, Mar 28, 2018 at 12:40 PM, Alex Efros <[email protected]> wro=
te:
>> Hi!
>>=20
>>> On Wed, Mar 28, 2018 at 06:06:00PM +0100, Robert Sharp wrote:
>>> Does anyone know of a good, post GRSecurity guide to reasonable security=

>>> for the kernel? In the absence of anything else I will have to go back
>>> to the KSPP list and start removing stuff until I can get a stable kerne=
l.
>>=20
>> I'm using https://github.com/minipli/linux-unofficial_grsec, but it lacks=

>> Spectre and Meltdown mitigation at the moment (see issues). Still, I
>> believe it's the best we can have now (better is probably paid GrSec, but=

>> AFAIK it's impossible or too costly to buy it for home or small business)=
.
>=20
> Previous contributors have access to the code, but it doesn't seem
> like there is any way to go that route anymore.
>=20

--Apple-Mail-810EE19F-BC9C-40A1-B729-D3BE8C741122
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto"><div><span></span></div><div><div></div><di=
v><span style=3D"background-color: rgba(255, 255, 255, 0);">Hi all,<br><br>I=
=E2=80=99ve been a grsecurity customer for a little over two years now, and m=
y use of it is as a small business, on Gentoo server installations. While I c=
an=E2=80=99t disclose the amount of money I=E2=80=99m paying publicly becaus=
e every deal is customized, I would encourage you to get in touch using the c=
ontact form on&nbsp;<a href=3D"http://grsecurity.net/" dir=3D"ltr" x-apple-d=
ata-detectors=3D"true" x-apple-data-detectors-type=3D"link" x-apple-data-det=
ectors-result=3D"0">grsecurity.net</a>&nbsp;and ask for a quote if you haven=
=E2=80=99t already.<br><br>You might just end up with an arrangement you can=
 afford, and grsec is still certainly worth having today. Not only for the f=
eature set, but also for the constant looking over the mainline Linux kernel=
 code, including fixing and backporting more fixes than the regular kernel s=
table releases, and for knowledge / emails giving context to important kerne=
l vulnerabilities when they occur.<br><br><br>Best,<br><br>=E2=80=93 Guillau=
me Ceccarelli&nbsp;</span></div><div><br>On 28 Mar 2018, at 20:22, R0b0t1 &l=
t;<a href=3D"mailto:[email protected]">[email protected]</a>&gt; wrote:<br><br=
></div><blockquote type=3D"cite"><div><span>On Wed, Mar 28, 2018 at 12:40 PM=
, Alex Efros &lt;<a href=3D"mailto:[email protected]">powerman@powerman=
.name</a>&gt; wrote:</span><br><blockquote type=3D"cite"><span>Hi!</span><br=
></blockquote><blockquote type=3D"cite"><span></span><br></blockquote><block=
quote type=3D"cite"><span>On Wed, Mar 28, 2018 at 06:06:00PM +0100, Robert S=
harp wrote:</span><br></blockquote><blockquote type=3D"cite"><blockquote typ=
e=3D"cite"><span>Does anyone know of a good, post GRSecurity guide to reason=
able security</span><br></blockquote></blockquote><blockquote type=3D"cite">=
<blockquote type=3D"cite"><span>for the kernel? In the absence of anything e=
lse I will have to go back</span><br></blockquote></blockquote><blockquote t=
ype=3D"cite"><blockquote type=3D"cite"><span>to the KSPP list and start remo=
ving stuff until I can get a stable kernel.</span><br></blockquote></blockqu=
ote><blockquote type=3D"cite"><span></span><br></blockquote><blockquote type=
=3D"cite"><span>I'm using <a href=3D"https://github.com/minipli/linux-unoffi=
cial_grsec">https://github.com/minipli/linux-unofficial_grsec</a>, but it la=
cks</span><br></blockquote><blockquote type=3D"cite"><span>Spectre and Meltd=
own mitigation at the moment (see issues). Still, I</span><br></blockquote><=
blockquote type=3D"cite"><span>believe it's the best we can have now (better=
 is probably paid GrSec, but</span><br></blockquote><blockquote type=3D"cite=
"><span>AFAIK it's impossible or too costly to buy it for home or small busi=
ness).</span><br></blockquote><blockquote type=3D"cite"><span></span><br></b=
lockquote><span></span><br><span>Previous contributors have access to the co=
de, but it doesn't seem</span><br><span>like there is any way to go that rou=
te anymore.</span><br><span></span><br></div></blockquote></div></body></htm=
l>=

--Apple-Mail-810EE19F-BC9C-40A1-B729-D3BE8C741122--