Re: Hardening a Kernel post hardened-sources
Robert Sharp <selinux-/[email protected]> Fri, 30 Mar 2018 16:37:51 +0100
| Newsgroups | gmane.linux.gentoo.hardened |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --------------DB60447B9D497225D3A350CC Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 8bit I requested a quote from GRsecurity and they told me that although they are looking at providing a package for personal customers they don't have one at the moment. They recommended minipli as the next best thing... What about the grsecurity-source overlay? On 29/03/18 11:47, Guillaume Ceccarelli wrote: > Hi all, > > I’ve been a grsecurity customer for a little over two years now, and > my use of it is as a small business, on Gentoo server installations. > While I can’t disclose the amount of money I’m paying publicly because > every deal is customized, I would encourage you to get in touch using > the contact form on grsecurity.net <http://grsecurity.net/> and ask > for a quote if you haven’t already. > > You might just end up with an arrangement you can afford, and grsec is > still certainly worth having today. Not only for the feature set, but > also for the constant looking over the mainline Linux kernel code, > including fixing and backporting more fixes than the regular kernel > stable releases, and for knowledge / emails giving context to > important kernel vulnerabilities when they occur. > > > Best, > > – Guillaume Ceccarelli > > On 28 Mar 2018, at 20:22, R0b0t1 <[email protected] > <mailto:[email protected]>> wrote: > >> On Wed, Mar 28, 2018 at 12:40 PM, Alex Efros <[email protected] >> <mailto:[email protected]>> wrote: >>> Hi! >>> >>> On Wed, Mar 28, 2018 at 06:06:00PM +0100, Robert Sharp wrote: >>>> Does anyone know of a good, post GRSecurity guide to reasonable >>>> security >>>> for the kernel? In the absence of anything else I will have to go back >>>> to the KSPP list and start removing stuff until I can get a stable >>>> kernel. >>> >>> I'm using https://github.com/minipli/linux-unofficial_grsec, but it >>> lacks >>> Spectre and Meltdown mitigation at the moment (see issues). Still, I >>> believe it's the best we can have now (better is probably paid >>> GrSec, but >>> AFAIK it's impossible or too costly to buy it for home or small >>> business). >>> >> >> Previous contributors have access to the code, but it doesn't seem >> like there is any way to go that route anymore. >> --------------DB60447B9D497225D3A350CC Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: 8bit <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> </head> <body text="#000000" bgcolor="#FFFFFF"> <div class="moz-cite-prefix">I requested a quote from GRsecurity and they told me that although they are looking at providing a package for personal customers they don't have one at the moment. They recommended minipli as the next best thing...<br> <br> What about the grsecurity-source overlay?<br> <br> On 29/03/18 11:47, Guillaume Ceccarelli wrote:<br> </div> <blockquote type="cite" cite="mid:467F3E15-D7B4-411F-994B-780871AA83A4-IyFa6exPGtwsy6BxJt0lzQ@public.gmane.org"> <meta http-equiv="content-type" content="text/html; charset=utf-8"> <div><span></span></div> <div> <div><span style="background-color: rgba(255, 255, 255, 0);">Hi all,<br> <br> I’ve been a grsecurity customer for a little over two years now, and my use of it is as a small business, on Gentoo server installations. While I can’t disclose the amount of money I’m paying publicly because every deal is customized, I would encourage you to get in touch using the contact form on <a href="http://grsecurity.net/" dir="ltr" x-apple-data-detectors="true" x-apple-data-detectors-type="link" x-apple-data-detectors-result="0" moz-do-not-send="true">grsecurity.net</a> and ask for a quote if you haven’t already.<br> <br> You might just end up with an arrangement you can afford, and grsec is still certainly worth having today. Not only for the feature set, but also for the constant looking over the mainline Linux kernel code, including fixing and backporting more fixes than the regular kernel stable releases, and for knowledge / emails giving context to important kernel vulnerabilities when they occur.<br> <br> <br> Best,<br> <br> – Guillaume Ceccarelli </span></div> <div><br> On 28 Mar 2018, at 20:22, R0b0t1 <<a href="mailto:[email protected]" moz-do-not-send="true">[email protected]</a>> wrote:<br> <br> </div> <blockquote type="cite"> <div><span>On Wed, Mar 28, 2018 at 12:40 PM, Alex Efros <<a href="mailto:[email protected]" moz-do-not-send="true">[email protected]</a>> wrote:</span><br> <blockquote type="cite"><span>Hi!</span><br> </blockquote> <blockquote type="cite"><span></span><br> </blockquote> <blockquote type="cite"><span>On Wed, Mar 28, 2018 at 06:06:00PM +0100, Robert Sharp wrote:</span><br> </blockquote> <blockquote type="cite"> <blockquote type="cite"><span>Does anyone know of a good, post GRSecurity guide to reasonable security</span><br> </blockquote> </blockquote> <blockquote type="cite"> <blockquote type="cite"><span>for the kernel? In the absence of anything else I will have to go back</span><br> </blockquote> </blockquote> <blockquote type="cite"> <blockquote type="cite"><span>to the KSPP list and start removing stuff until I can get a stable kernel.</span><br> </blockquote> </blockquote> <blockquote type="cite"><span></span><br> </blockquote> <blockquote type="cite"><span>I'm using <a href="https://github.com/minipli/linux-unofficial_grsec" moz-do-not-send="true">https://github.com/minipli/linux-unofficial_grsec</a>, but it lacks</span><br> </blockquote> <blockquote type="cite"><span>Spectre and Meltdown mitigation at the moment (see issues). Still, I</span><br> </blockquote> <blockquote type="cite"><span>believe it's the best we can have now (better is probably paid GrSec, but</span><br> </blockquote> <blockquote type="cite"><span>AFAIK it's impossible or too costly to buy it for home or small business).</span><br> </blockquote> <blockquote type="cite"><span></span><br> </blockquote> <span></span><br> <span>Previous contributors have access to the code, but it doesn't seem</span><br> <span>like there is any way to go that route anymore.</span><br> <span></span><br> </div> </blockquote> </div> </blockquote> <p><br> </p> </body> </html> --------------DB60447B9D497225D3A350CC--