LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-09-2018, 02:09 AM   #1
thecrazyalpine
LQ Newbie
 
Registered: Oct 2018
Posts: 1

Rep: Reputation: Disabled
Lightbulb Enable application with grsecurity


Hi, I am new to here. This is my first question.
I am using debian 9 with mate desktop. I have enabled apparmor. Used backports to install prepatched grsec kernel. Now with carefull work I disabled mprotect for libreoffice and firefox to make them usable. But I need precise executable files for bleachbit, debian report bug, synaptic package manager to configure it for grsecurity and recommended paxctl flag.
I especially want help for recommended paxctl flag of most common apps and their path to execute them. Also want a default tight security settings for global defaults, enabling chroot and several features usable for security. Except RBAC because I am satisfied with apparmor.
Also I want to ensure tight kernel configuration like seccomp, namespaces and several kernel executable features(if these are compatible with pax then also I will use them). But how to configure it and compile install, reload it into grub and delete the optional kernel.
Oh yes, I also want to block root and run xorg rootless.
Here is my question. I am quite a newbie. So advance apology for any commited mistakes.
 
Old 10-23-2018, 06:02 PM   #2
RickDeckard
Member
 
Registered: Jan 2014
Location: Canton, Georgia, USA
Distribution: Debian 12
Posts: 205

Rep: Reputation: Disabled
I haven't used GRSecurity since before the big announcement that Brad and his team were closing off the source. That being said, with all respect, I think your question is too broad:

1. Rootless Xorg would be more of a Debian security team issue if they chose to implement it, and not something you can tweak GRSec settings to bring about, although keeping "disable IOPL/IOPERM" unchecked should keep you in the Xorg money period.

2. Most flag configuration issues for day to day use (at least only in my own experience) are really going to be disabling MPROTECT.

3. What do you mean by "block root"? If you want to forego root login, how well that works out would instead be dependent on your distro. If you want to confine root's abilities like the SELinux sysadm_u user mapping might, that is more of a RBAC thing, sorry.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Enable debug logging in application? yaplej Programming 2 08-20-2014 10:55 AM
GRsecurity dbi Slackware 6 08-28-2006 11:50 PM
grsecurity and 2.6.11.7 houler Slackware 2 05-07-2005 02:21 AM
How to enable root to run graphical application in user log in xgreen Slackware 4 03-07-2005 06:39 AM
enable separate terminal for application i/o in KDevelop mrosati Linux - Software 0 04-21-2004 09:56 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:10 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration