<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Gentoo | Hardened</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>12 Feb  2012 09:00:53 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Gentoo | Hardened</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>Re: [gentoo-dev] profiles/features/64bit-native/package.use.mask contents redundancy</title>
<description>[. CCed gentoo-hardened@lists.gentoo.org  to warn against possible breakage. Touching  profiles make me nervous.  TS: http://archives.gentoo.org/ge</description>
<pubDate>11 Feb  2012 10:48:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/247694</link>
</item><item>
<title>gcc 4.5.3 doesn&amp;#039;t build on x86 hardened profile</title>
<description>Howdy folks, I recently tried to recompile some packages and I discovered that GCC 4.5.3, the current default version in the hardened profile will no</description>
<pubDate>05 Feb  2012 19:28:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/247454</link>
</item><item>
<title>New sudo format string vuln</title>
<description>Not sure how much testing anyone else has done (and it warrants more testing), but I just tested this on a rather out-of-date machine running hardened</description>
<pubDate>31 Jan  2012 07:12:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/247209</link>
</item><item>
<title>SELinux base policy rev 12 in hardened-dev</title>
<description>Hi guys, A small update to the SELinux policies in our favorite distribution. This one pulls in the following changes: bug #399113:  Be able to di</description>
<pubDate>29 Jan  2012 09:10:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/247053</link>
</item><item>
<title>Missmatch in digests</title>
<description>Hello, I&amp;#039;ve just made sync, and I got following errors during calulacting updates: * /usr/portage/sec-policy/selinux-base-policy/selinux-base-policy</description>
<pubDate>29 Jan  2012 05:38:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/247037</link>
</item><item>
<title>Re: Please test hardened-sources 2.6.32-r88 and3.2.2</title>
<description>Dnia 27 stycznia 2012 17:06 &amp;quot;Tóth Attila&amp;quot; &amp;lt;atoth@atoth.sote.hu&amp;gt; napisał(a): &amp;gt; And this one is from my laptop: &amp;gt; vmalloc: allocation failure: 0 byte</description>
<pubDate>27 Jan  2012 09:38:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/246890</link>
</item><item>
<title>Please test hardened-sources 2.6.32-r88 and 3.2.2</title>
<description>Hi everyone, I just added hardened-sources 2.6.32-r88 and 3.2.2 to the tree. They address CVE-2012-0056. I&amp;#039;ve tested and they do indeed resist the</description>
<pubDate>27 Jan  2012 05:37:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/246864</link>
</item><item>
<title>Security Level: high/server/workstation/virtualization</title>
<description>Hi! If you ever wonder how exactly differs predefined security levels, you&amp;#039;ll find this information here. :) I&amp;#039;ve compared them, plus I did some benc</description>
<pubDate>27 Jan  2012 05:26:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/246863</link>
</item><item>
<title>openrc-0.9.8.2 screwed up bonding config</title>
<description>I&amp;#039;m sorry for being offtopic, but this is the list I can rely on. I&amp;#039;ve just upgraded openrc from 0.9.4 to 0.9.8.2 and my server went offline. After st</description>
<pubDate>25 Jan  2012 17:15:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/246771</link>
</item><item>
<title>Interesting: CVE-2012-0056</title>
<description>Please take a look at on this exploit: http://blog.zx2c4.com/749 It is interesting to think about /proc/pid/mem protection and about building su with</description>
<pubDate>23 Jan  2012 15:49:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/246715</link>
</item><item>
<title>Meeting log 2012-01-18 20:00UTC</title>
<description>Hi Log from the meeting /Magnus (Zorry)</description>
<pubDate>23 Jan  2012 12:11:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/246701</link>
</item><item>
<title>New amd64 install</title>
<description>I have two hardened gentoo systems I&amp;#039;m running for many years now. I&amp;#039;ve installed the personal server in 2004. The laptop started in 2005. Now the tim</description>
<pubDate>14 Jan  2012 12:22:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/246177</link>
</item><item>
<title>SELinux base policy rev 11 in hardened-dev</title>
<description>Hi guys, I haven&amp;#039;t merged hardened-development overlay with the main tree yet because I had to make sure that the changes in the policycoreutils woul</description>
<pubDate>10 Jan  2012 11:53:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/246018</link>
</item><item>
<title>Gentoo reintroduction of rsbac-sources</title>
<description>Hi everyone, A long time ago, Gentoo used to provide RSBAC sources. For those of you unfamiliar with RSBAC = rules set based access control, it prov</description>
<pubDate>07 Jan  2012 13:08:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/245898</link>
</item><item>
<title>New glibc feature caught sed in action while revdep-rebuild?</title>
<description>I&amp;#039;ve just installed a new glibc, since the latest dev-lang/R now doesn&amp;#039;t have any requirements about it. On two systems I got the following messages</description>
<pubDate>04 Jan  2012 14:12:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/245623</link>
</item><item>
<title>mount: unknown filesystem type &amp;#039;selinuxfs&amp;#039;</title>
<description>Hi: I try to make my system selinux enabled and followed the steps from http://www.gentoo.org/proj/en/hardened/selinux/selinux-handbook.xml?part=2&amp;amp;ch</description>
<pubDate>04 Jan  2012 08:09:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/245572</link>
</item><item>
<title>Re: aufs3.0 fails to emerge on Gentoo hardened and kernel 3.0.4</title>
<description>On 3 Jan 2012 at 18:34, Andrea Zuccherelli wrote: &amp;gt; hfsnotify.c:208:2: error: assignment of read-only member &amp;#039;br_hfsn_ops&amp;#039; &amp;gt; &amp;gt; I found this to be ca</description>
<pubDate>03 Jan  2012 10:02:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/245503</link>
</item><item>
<title>i386 uclibc stages based on 0.9.32.1, both hardened and vanilla</title>
<description>Hi, I know some people were interested in this, so here it is. I&amp;#039;ve built two stage4 tarballs (stage3 + other stuff for a full development env). The</description>
<pubDate>03 Jan  2012 07:53:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/245452</link>
</item><item>
<title>SELinux base policy rev 10 in hardened-dev</title>
<description>Hi guys, Assuming you don&amp;#039;t kill me for not using hexadecimal notations, rev 10 is now out right after rev 9. Revision 10 of selinux-base-policy come</description>
<pubDate>30 Dec  2011 12:02:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/245102</link>
</item><item>
<title>hardened-sources &amp;amp; tp_smapi, firefox-9.0 install stucks</title>
<description>Positive feedback: New tp_smapi ebuild (0.41) based on the forked Debian source compiles fine with hardened-sources-3.1.5 and hardened-sources-3.1.6,</description>
<pubDate>29 Dec  2011 15:09:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/245060</link>
</item><item>
<title>SELinux base policy rev 9 in hardened-dev</title>
<description>Hi guys, In the hardened-dev overlay you can now find the SELinux policy revision 9 (and its affiliated modules). The included changes are: - &amp;lt;bug #</description>
<pubDate>27 Dec  2011 10:05:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/244974</link>
</item><item>
<title>Changes to the predefined grsec profiles: GRKERNSEC_HARDENED_{SERVER,WORKSTATION,VIRTUALIZATION}</title>
<description>Hi everyone, For a while now, we&amp;#039;ve been supporting three predefined grsec profiles in the hardened-sources kernel. Upstream provides four. These a</description>
<pubDate>26 Dec  2011 10:57:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/244942</link>
</item><item>
<title>Meeting 2011-12-14 20:00UTC log</title>
<description>Hi Here is the meeting log. /Magnus (Zorry)</description>
<pubDate>18 Dec  2011 14:48:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/244612</link>
</item><item>
<title>gcc-4.4.6 - says &amp;quot;arch is not supported&amp;quot; &amp;quot;hope you know what you are doing&amp;quot;?</title>
<description>So I am building in a chroot an x86 system: CFLAGS=&amp;quot;-march=k6-2 -Os -pipe -fomit-frame-pointer&amp;quot; CXXFLAGS=&amp;quot;${CFLAGS}&amp;quot; LDFLAGS=&amp;quot;-Wl,-z,relro&amp;quot; CHOST=&amp;quot;i</description>
<pubDate>12 Dec  2011 16:08:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/244289</link>
</item><item>
<title>Re:</title>
<description>huh?  ________________________________ From: &amp;quot;simon.cruddas@othermedia.com&amp;quot; &amp;lt;simon@othermedia.com&amp;gt; To: gentoo-hardened@lists.gentoo.org Sent: Monda</description>
<pubDate>12 Dec  2011 12:26:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/244272</link>
</item><item>
<title>[no subject]</title>
<description>-- simon cruddas | systems architect +44 (0)20 7089 5971 | pgp : 0xC0D7FAD3</description>
<pubDate>12 Dec  2011 12:20:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/244271</link>
</item><item>
<title>PAX/Grsecurity Enabled Distros</title>
<description>Does anyone know of any prebuilt desktop distros based on hardened gentoo. I&amp;#039;ve just found anikos.org but it still looks like early days? -- Kc</description>
<pubDate>12 Dec  2011 11:34:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/244261</link>
</item><item>
<title>SELinux base policy rev 8 in hardened-dev</title>
<description>Hi guys, I just pushed rev 8 of selinux-base-policy (and the various policy modules that have changes in them since rev 7). The included changes are:</description>
<pubDate>11 Dec  2011 05:48:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/244190</link>
</item><item>
<title>New Server, considering hardened, need pointers to tfm...</title>
<description>Hello all, I&amp;#039;m considering rolling out a new server with gentoo, but wanted to base it on the hardened profile, but the gentoo docs I&amp;#039;ve read so far</description>
<pubDate>10 Dec  2011 12:17:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/244160</link>
</item><item>
<title>The last browser (opera) to work with grsec by default may be succombing (ptrace).</title>
<description>Has anyone tried Opera 11.60 with a grsecurity patched kernel. 11.52 worked fine but 11.60 is segfaulting with &amp;quot;denied ptrace of /usr/lib/opera/opera</description>
<pubDate>09 Dec  2011 05:17:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/244098</link>
</item><item>
<title>SELinux base policy rev 7 in hardened-dev</title>
<description>The SELinux base policy revision 7 has been pushed to the hardened-dev overlay. Base policy r5 has been stabilized in the tree. Changes in rev 7 are:</description>
<pubDate>27 Nov  2011 10:59:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/243271</link>
</item><item>
<title>Help with su</title>
<description>One of the more important things that is currently broken on my system when I switch on enforcing mode for SELinux is the su command. Mostly likely I</description>
<pubDate>25 Nov  2011 19:32:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/243118</link>
</item><item>
<title>check-reqs_pkg_pretend checks /tmp in pkg_pretend() for libreoffice-3.4.4.2-r1!</title>
<description>I know that it&amp;#039;s not hardened related, but I&amp;#039;m curious if you experienced this problems as well. While I try to compile recent libreoffice I got an e</description>
<pubDate>25 Nov  2011 13:29:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/243088</link>
</item><item>
<title>SELinux bug reporting guide</title>
<description>Hi folks, An early attempt to describe how to best report SELinux bugs. It currently only focuses on policy bugs, since those are the ones we target</description>
<pubDate>22 Nov  2011 12:14:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/242926</link>
</item><item>
<title>Meeting log 2011-11-17 20:00UTC</title>
<description>Hi Here is the meeting log form the meeting 2011-11-17 20:00UTC /Magnus</description>
<pubDate>20 Nov  2011 14:07:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/242859</link>
</item><item>
<title>hardened/index.xml shows incorrect commit date</title>
<description>Hey, Date of document was not changed in last commit of /proj/hardened/en/index.xml. I think this date should be changed, so: s|&amp;lt;date&amp;gt;2011-08-12&amp;lt;/da</description>
<pubDate>18 Nov  2011 06:31:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/242771</link>
</item><item>
<title>udev-171-r2 and 3.0.9-hardened</title>
<description>I did a sync and a world update earlier today and among the updates was the 3.0.9 hardened sources. I built the new kernel with the same settings as</description>
<pubDate>17 Nov  2011 18:18:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/242744</link>
</item><item>
<title>SELinux base policy rev 6 in hardened-dev</title>
<description>Hi all, I have pushed out an update on the SELinux policies in hardened-dev. The changes include: - #389579 (Mismatch on amavisd.conf context) - #38</description>
<pubDate>12 Nov  2011 13:25:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/242368</link>
</item><item>
<title>CUDA</title>
<description>Hello, May I ask if nvidia is still hardend unfriendly? I need CUDA available. Alternativly may I get what is wrong with this driver, I may check ne</description>
<pubDate>12 Nov  2011 11:11:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/242364</link>
</item><item>
<title>Secpolicy collision</title>
<description>Hello, I don&amp;#039;t tracked mails so sorry if I resended same information. I thnik there is collision between selinux-gnupg selinux-gpg packages, collis</description>
<pubDate>11 Nov  2011 03:17:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/242213</link>
</item><item>
<title>refpolicy and Gentoo ebuilds</title>
<description>I&amp;#039;ve started poking around in the refpolicy source to help me learn about the correct policy module style by looking at other examples. I&amp;#039;ve noticed</description>
<pubDate>07 Nov  2011 17:52:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/242044</link>
</item><item>
<title>Tin Hat 20111107 released.</title>
<description>Hi everyone, I&amp;#039;d like to announce that a new release of Tin Hat is out. Tin Hat is a fully featured Linux desktop based on Hardened Gentoo which runs</description>
<pubDate>07 Nov  2011 03:10:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/241990</link>
</item><item>
<title>Grsec X11 Rbac Selinux Priviledged/Raw I/O Mprotect Firefox</title>
<description>I&amp;#039;ve been using OpenBSD for a while now which has priv dropping X and the machdep.allowaperture=[0|1|2]. Theo has said firefox also annoyingly uses it</description>
<pubDate>06 Nov  2011 15:19:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/241945</link>
</item><item>
<title>On the right track?</title>
<description>Looks like I&amp;#039;m the second newbie in a week to introduce himself to the list. I&amp;#039;ve been a unix/Linux systems administrator for over a decade, and have</description>
<pubDate>03 Nov  2011 18:44:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/241800</link>
</item><item>
<title>Asterisk...</title>
<description>This fixed quite some messages. module astnb 1.0; require {     type var_run_t;     type var_log_t;     type asterisk_t;     type va</description>
<pubDate>02 Nov  2011 18:24:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/241759</link>
</item><item>
<title>Eaccelerator... amavis... (file context)</title>
<description>Here definitely is a bug in the file contexts. The eaccelerator stuff in the default implementation is referencing /var/cache/php-eaccelerator... /v</description>
<pubDate>02 Nov  2011 17:46:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/241757</link>
</item><item>
<title>exim / amavis / Clamav</title>
<description>Here I am not sure... exim has some problems, amavis has various problems &amp;amp; clamav has some problems. Exim produces: ---8&amp;lt;--- module exim-nb 1.0;</description>
<pubDate>02 Nov  2011 17:40:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/241756</link>
</item><item>
<title>fail2ban...</title>
<description>Fail2ban seems to lack the next ---8&amp;lt;--- module fail2ban-nb 1.0; require {     type fail2ban_t;     class capability dac_override; } #=====</description>
<pubDate>02 Nov  2011 17:34:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/241755</link>
</item><item>
<title>nrpe...</title>
<description>This is also used for the nagios stuff: ---8&amp;lt;--- module nrpe 1.0; require {     type nrpe_t;     type proc_mdstat_t;     type system_cro</description>
<pubDate>02 Nov  2011 17:32:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/241754</link>
</item><item>
<title>miniupnpd...</title>
<description>Ok, it shouldn&amp;#039;t be used, but sometimes, it is needed. The folling seems to help fix stuff: ---8&amp;lt;--- module miniupnpdnb 1.0; require {     type</description>
<pubDate>02 Nov  2011 17:30:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/241753</link>
</item><item>
<title>Nagios...</title>
<description>Nagios is not exactly installed, just nrpe is. Several audit messages indicate that the checkdisk_plugin has problems, from these reports the followin</description>
<pubDate>02 Nov  2011 17:28:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/241752</link>
</item><item>
<title>Newbee alarm....</title>
<description>Well.. at least is nice to introduce one-self. Hi, I am a self-employed OpenVMS Cluster/systems manager by profession and run some linux on the side.</description>
<pubDate>02 Nov  2011 17:22:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/241751</link>
</item><item>
<title>I&amp;#039;d like to deprecate some older stabilize hardened-sources</title>
<description>Hi everyone, There are some older stable hardened sources that I&amp;#039;d like to deprecate. They have some known issues which have been fixed in later sta</description>
<pubDate>30 Oct  2011 13:13:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/241633</link>
</item><item>
<title>Guinea pigs ... ehm ... testers required!</title>
<description>Hi everyone, As you may know, I&amp;#039;ve been working on a set of utilities to use with a PaX enabled kernel. These are installed with sys-app/elfix which</description>
<pubDate>23 Oct  2011 09:50:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/241286</link>
</item><item>
<title>&amp;quot;/usr/bin/install: cannot stat `id.mo&amp;#039;: No such file or directory&amp;quot; when installing policycoreutils</title>
<description>Hi All, I am following the selinux-guide Sven updated recently on a VM with a clean install. I started with the hardened stage 3 as recommended and a</description>
<pubDate>19 Oct  2011 05:32:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/240983</link>
</item><item>
<title>Updated SELinux handbook</title>
<description>Hi lads, I had some issues with my previous attempt on the SELinux handbook (a few chapters were too detailed, others lacked the detail needed) so I</description>
<pubDate>15 Oct  2011 11:41:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/240773</link>
</item><item>
<title>Meeting log 2011-10-05</title>
<description>Hi Log from the meeting 2011-10-05 20:00UTC /Magnus</description>
<pubDate>09 Oct  2011 06:42:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/240239</link>
</item><item>
<title>offtopic: libpng upgrade</title>
<description>I&amp;#039;ve suspected, that it won&amp;#039;t be a torch-light procession. But reality exceeded my expectations. Around 60 packages failed out of approx 100! I&amp;#039;ve fol</description>
<pubDate>22 Sep  2011 12:23:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/239245</link>
</item><item>
<title>Testing request for sys-apps/elfix-0.2.0</title>
<description>Hi everyone, I&amp;#039;m working towards forcing a consistency in how we pax mark our binaries. The RFC for the design is at http://git.overlays.gentoo.org</description>
<pubDate>20 Sep  2011 05:14:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/239088</link>
</item><item>
<title>elog logrotate portage problems</title>
<description>Some weeks before logrotate started to complain on elog permissions. I&amp;#039;ve added the necessary su lines to the configuration. That was also officially</description>
<pubDate>18 Sep  2011 05:52:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/238853</link>
</item><item>
<title>Bringing back RSBAC sources</title>
<description>Hi everyone, It looks like upstream RSBAC is active again. Gentoo used to have rsbac-sources, so it would be nice to get them back. I&amp;#039;m not sure ri</description>
<pubDate>04 Sep  2011 16:07:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/237565</link>
</item><item>
<title>bonding grsec logs about capabilites and alias during boot</title>
<description>In May I started seeing grsec messages about bonding. It was compiled into the kernel for ages, serving the primary multi-port NIC connected to a Cisc</description>
<pubDate>03 Sep  2011 08:36:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/237519</link>
</item><item>
<title>Meeting log</title>
<description>Sorry /Magnus</description>
<pubDate>31 Aug  2011 16:02:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/237374</link>
</item><item>
<title>Meeting log 2011-08-24 20:00UTC</title>
<description>Hi The log from the meeting 2011-08-24 20:00UTC I was reselected as lead for the hardened project. Tankyou all for the support. /Magnus</description>
<pubDate>31 Aug  2011 16:01:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/237373</link>
</item><item>
<title>Update on SELinux development guideline(s)</title>
<description>Hi guys, In the &amp;quot;Gentoo Hardened SELinux Development Policy&amp;quot; [1] we have a section requiring development to use the &amp;#039;gentoo_&amp;#039; prefix. The reason for</description>
<pubDate>23 Aug  2011 11:10:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/236973</link>
</item><item>
<title>Stabilizing the new selinux profiles</title>
<description>Hi everyone, Back in May, I added new feature/selinux profiles which we would like to stabilize soon. These were structured to parallel the selinux/</description>
<pubDate>21 Aug  2011 04:10:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/236825</link>
</item><item>
<title>SELinux base policy r2 in hardened-dev overlay</title>
<description>Hi guys, I have just pushed selinux-base-policy--2.20110726-r2 to the hardened-dev overlay. There are not that many changes in it (although &amp;quot;not many</description>
<pubDate>19 Aug  2011 13:51:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/236747</link>
</item><item>
<title>secploicy-consolekit uses obsolete hal</title>
<description>I tried to install selinux-consolekit-2.20101213.ebuild and I got error libsepol.print_missing_requirements: consolekit&amp;#039;s global requirements were no</description>
<pubDate>14 Aug  2011 18:20:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/236331</link>
</item><item>
<title>Remove obsolete pmask entries from profiles</title>
<description>Hi guys, Many hardened profiles still pmask the following GCCs: =sys-devel/gcc-4.3.2* =sys-devel/gcc-4.4.1* =sys-devel/gcc-4.4.3-r2 =sys-devel/gcc-4</description>
<pubDate>14 Aug  2011 01:17:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/236315</link>
</item><item>
<title>SeLinux system_u:system_r:initrc_t inside KDE</title>
<description>Hello, Problem mainly is about starnge ID system_u:system_r:initrc_t I have inside KDE&amp;#039;s konsole (all applications started / KDE service has it too)</description>
<pubDate>10 Aug  2011 11:57:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/236099</link>
</item><item>
<title>Updates on SELinux documentation</title>
<description>Hiya, Would it be possible to update the following files from the hardened-docs.git repository to the main (gentoo) one? selinux/hb-intro-concepts.x</description>
<pubDate>10 Aug  2011 11:15:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/236098</link>
</item><item>
<title>Troubleshooting FIFO pipes with bad security contexts...</title>
<description>I&amp;#039;m trying to chase down an AVC message coming from procmail. I&amp;#039;m having a problem figuring out how to research, troubleshoot, or fix bad FIFO pipe</description>
<pubDate>06 Aug  2011 09:50:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/235943</link>
</item><item>
<title>Re:</title>
<description>I only get a 404 error On Fri, Aug 5, 2011 at 1:53 PM, Jared Thomas &amp;lt;thomas_chaos@yahoo.com&amp;gt; wrote: &amp;gt; http://alumnispecs.com/shop/admin/images/graph</description>
<pubDate>05 Aug  2011 05:00:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/235899</link>
</item><item>
<title>Update on selinux-policy-2 eclass</title>
<description>Hi * To allow for more manageable patching on our selinux policies (since Matthew will bombard me anyhow with things to fix ;-) and not to clutter th</description>
<pubDate>02 Aug  2011 00:19:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/235768</link>
</item><item>
<title>SELinux and gdm/kdm -- not setting sesson context?</title>
<description>I just installed the latest SELinux stuff from the hardened-development overlay onto my laptop, currently using the targeted profile (though I&amp;#039;ve als</description>
<pubDate>30 Jul  2011 18:05:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/235600</link>
</item><item>
<title>SELinux base policy r21 in hardened-dev.git</title>
<description>Hi all, Just to let you know r21 is now available in hardened-dev.git. No major changes here. Most of them are for Portage support to allow emerge, e</description>
<pubDate>24 Jul  2011 04:10:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/235235</link>
</item><item>
<title>Re: SElinux tests</title>
<description>Hi Nick, Thanks for the report, but would you be so kind as to open up bug reports for each of the issues at https://bugs.gentoo.org/ --Tony On 07/</description>
<pubDate>24 Jul  2011 02:25:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/235234</link>
</item><item>
<title>SELinux base policy r20 in hardened-dev.git, now with MCS/MLS</title>
<description>Hi all, I&amp;#039;ve pushed selinux-base-policy-2.20101213-r20 to the hardened-dev overlay. This update contains the following changes since r19: - Introduc</description>
<pubDate>21 Jul  2011 12:42:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/235024</link>
</item><item>
<title>SELinux bughunt</title>
<description>Hi guys, The SELinux bugs are &amp;quot;piling&amp;quot; up but most of them are resolved and I&amp;#039;d like to use the STATUS field to keep track of which bugs are actually</description>
<pubDate>21 Jul  2011 03:06:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/234969</link>
</item><item>
<title>[solved] Re: mprotect question</title>
<description>Hi, I seem to have messed up my mail accounts and this list seems only to accept submissions from members, so here what I wrote to Anthony before. T</description>
<pubDate>15 Jul  2011 04:02:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/234634</link>
</item><item>
<title>Log from meeting 2011-07-13 20:00 UTC</title>
<description>Hi Here is the log from the meeting we did have on 2011-07-13 20:00UTC /Magnus (Zorry)</description>
<pubDate>14 Jul  2011 14:44:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/234609</link>
</item><item>
<title>mprotect question</title>
<description>Hi, I successfully switched to hardened profile during the last week and it was quite painless. I think I can hand out some praise for the great work</description>
<pubDate>14 Jul  2011 02:54:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/234574</link>
</item><item>
<title>[no subject]</title>
<description>http://www.persephoneshaven.com/wp-content/themes/test.html</description>
<pubDate>13 Jul  2011 00:51:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/234537</link>
</item><item>
<title>selinux puppet update for 2.6.8</title>
<description>First, puppet and puppetmaster are both in /usr/bin not /usr/sbin anymore And here is what I needed to add to the policy. module puppetlocal 1.0; r</description>
<pubDate>10 Jul  2011 14:49:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/234423</link>
</item><item>
<title>Updates on SELinux (base) policy and packages</title>
<description>Hi lads, I&amp;#039;ve pushed a few changes to the hardened-dev.git overlay, ready for your mass inspection and testing. The changes include: - sec-policy/se</description>
<pubDate>07 Jul  2011 11:51:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/234229</link>
</item><item>
<title>checksum of stage3-amd64-hardened-20110625.tar.bz2</title>
<description>Hi, does anybody know why the checksum of stage3-amd64-hardened-20110625.tar.bz2 (26-Jun-2011) doesn&amp;#039;t match?  -- Regards Dave -- http://www.fast</description>
<pubDate>29 Jun  2011 18:45:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/233745</link>
</item><item>
<title>Problems with re-emerging openssh</title>
<description>Hello everybody, I use hardened gentoo, now with disabled grsecurity, and I can&amp;#039;t emerge openssh because it is unable to find libpam even though it r</description>
<pubDate>28 Jun  2011 06:47:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/233645</link>
</item><item>
<title>SELinux and KDE4.6.3</title>
<description>Hi all, I&amp;#039;ve Gentoo with KDE4.5.3 and SELinux enforcing targeted enabled plus grsecurity working fine. But KDE4.6.3 on a new system has difficulties</description>
<pubDate>23 Jun  2011 07:18:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/233161</link>
</item><item>
<title>SELinux policy for nginx, or include in apache?</title>
<description>Hi folks, As per bug #368795 [1] we have an open request to include a SELinux policy module for the nginx webserver. However, while working on this,</description>
<pubDate>15 Jun  2011 10:45:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/232624</link>
</item><item>
<title>Tips for upgrading to the current stable gentoo hardened?</title>
<description>Hi all, I&amp;#039;ve got a machine, which hasn&amp;#039;t been upgraded for some 2 years or less. It has GCC-4.3.4 and now I tried to upgrade to 4.5.2, but something</description>
<pubDate>15 Jun  2011 03:55:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/232592</link>
</item><item>
<title>Tin Hat 20110613 released.</title>
<description>Hi everyone, I&amp;#039;d like to announce that a new release of Tin Hat is out. Tin Hat is a fully featured Linux desktop based on Hardened Gentoo which runs</description>
<pubDate>13 Jun  2011 15:45:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/232520</link>
</item><item>
<title>Hardened stage3 tarballs</title>
<description>It looks like these stopped being published:  http://distfiles.gentoo.org/releases/amd64/current-stage3/ Any reason? They can still be found here,</description>
<pubDate>03 Jun  2011 09:08:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/231773</link>
</item><item>
<title>RFC - SELinux module documentation</title>
<description>Hi all, One of the &amp;quot;difficulties&amp;quot; of working with SELinux is that the policy that is pushed by default is tailored towards a default installation usi</description>
<pubDate>02 Jun  2011 09:52:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/231692</link>
</item><item>
<title>[no subject]</title>
<description>http://jamescotier.com/images/site.html</description>
<pubDate>25 May  2011 15:48:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/231211</link>
</item><item>
<title>Project page changes, roadmap and support matrix</title>
<description>Hi all, I have taken the liberty to update the SELinux subproject page a bit (see [1], nothing major there). During the page review I thought about a</description>
<pubDate>24 May  2011 13:55:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/231144</link>
</item><item>
<title>bonding module auto-loading</title>
<description>After a week I think I&amp;#039;ve sorted out nearly all issues about openrc on my systems. Bonding was compiled into the kernel. Upon I tried to echo mode 4 (</description>
<pubDate>20 May  2011 04:11:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/231011</link>
</item><item>
<title>New selinux &amp;quot;feature&amp;quot; profile</title>
<description>Hi everyone, Tomorrow I&amp;#039;ll be adding a new selinux &amp;quot;feature&amp;quot; profile to the tree. The idea behind this is like other features, it can be stacked on t</description>
<pubDate>16 May  2011 19:00:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/230761</link>
</item><item>
<title>How openrc check the state of services?</title>
<description>Just switched to openrc + baselayout2. Using grsecurity RBAC. During the shutdown process I see endless countdowns for each service waiting for other</description>
<pubDate>15 May  2011 17:49:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/230633</link>
</item><item>
<title>SELinux policy and openrc</title>
<description>Hi all, I&amp;#039;ve put selinux-base-policy-2.20101213-r14 in the hardened-dev.git overlay. Its main addition is support for openrc (which is now stable and</description>
<pubDate>13 May  2011 13:06:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/230485</link>
</item><item>
<title>hardened-sources-2.6.38-r* problems at the very beginning</title>
<description>I gave a try to hardened-sources-2.6.38-r1 and -r2 on my laptop. Both version get stuck at the very beginning of the boot process: &amp;quot; Decompressing Lin</description>
<pubDate>06 May  2011 02:11:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/gentoo/hardened/230001</link>
</item>
</channel>
</rss>

