store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Thu May 23, 2013 7:30 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 2 posts ] 
Author Message
 Post subject: Gradm and RBAC support
Unread postPosted: Thu May 17, 2012 1:40 am 
Offline
Forum User
Forum User

Joined: Tue Mar 06, 2012 5:23 pm
Posts: 7
Location: Melbourne
Does ASL fully support RBAC and Gradm? At the moment RBAC is disabled. Do you have any advise about using it with ASL? Shall we keep it disabled or could use it's features?


Top
 Profile  
 
 Post subject: Re: Gradm and RBAC support
Unread postPosted: Thu May 17, 2012 6:03 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3245
Location: Chantilly, VA
Quote:
Does ASL fully support RBAC and Gradm? At the moment RBAC is disabled. Do you have any advise about using it with ASL? Shall we keep it disabled or could use it's features?


Yes its fully supported. The best way to use it is to generate a least privilige policy for your system in learning mode. The process for doing that is documented here:

http://en.wikibooks.org/wiki/Grsecurity ... rning_Mode

From there, you will need to tune the policy a little further based on your needs. This will generate a very tight policy, which in practice is a bit too tight for a shared hosting system, so if you are doing shared hosting you'll need to loosen up the policy.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 2 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group