LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian
User Name
Password
Debian This forum is for the discussion of Debian Linux.

Notices


Reply
  Search this Thread
Old 02-24-2014, 06:33 AM   #1
bryn1u
LQ Newbie
 
Registered: Feb 2014
Posts: 9

Rep: Reputation: Disabled
Hardening Debian 7 dpkg-buildflags - pie, stackprotector, etc..


Hi everyone,

I was reading tutorial https://wiki.debian.org/Hardening, https://wiki.debian.org/HardeningWalkthrough and i was wondering how to use it. I've installed Debian 7 and i want to rebuild all packages with -fstack-protector-all and other options using hardening-wrapper/dpkg-buildflags. I would like to know is it any sense do it or if someone did it ?

Greetz,
bryn1u
 
Old 03-02-2014, 05:22 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
In my opinion it makes sense only if your threatscape points you to implementing measures like that, and if you have no alternatives and if trade-offs are not acceptable (that's and-and, not or-or). I'm saying it this way because you must understand that it will take knowledge and time troubleshooting problems you're bound to encounter and some effort maintaining those setups having to rebuild and QA packages when updates are released. So at this point (lack of nfo) only you can gauge if it is acceptable in terms of in what way this enhances security significantly or not, time, effort, knowledge. Ideally you should have a separate build server with automated build scripts and a staging machine to debug and perform quality assurance on for each of the machine roles you have in production.

It would be helpful if your reply explains why you think you need it.


///NTLB
 
Old 03-04-2014, 12:23 AM   #3
bryn1u
LQ Newbie
 
Registered: Feb 2014
Posts: 9

Original Poster
Rep: Reputation: Disabled
Destination to the server with shell account, possibility compile and run own software that's why i need this solution.
 
Old 03-04-2014, 04:39 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Well, I outlined what I think the decision making process should include and why and your reply doesn't change that, so.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Hardening Debian (Wheezy) on the desktop with KDE. edbarx Debian 5 04-09-2012 12:52 AM
hardening a debian squeeze server rbees Linux - Server 3 03-08-2012 10:14 PM
Hardening my Debian server locust76 Linux - Security 1 11-17-2011 04:04 AM
LXer: Hardening The Linux Kernel With Grsecurity (Debian) LXer Syndicated Linux News 0 11-19-2008 02:30 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian

All times are GMT -5. The time now is 11:45 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration