WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

Re: [Xen-users] Hardened Xen

On Mon, 18 Dec 2006 10:55:26 +0100
Alexander Thiem <Alexander@xxxxxxxxxxxx> wrote:

> And another question...
> 
> I did not found anything on a working kernel with grsecurity/pax and
> xen patches at the same time.
> So what about using a hardened kernel in the domU while using a
> normal kernel in dom0 - does this make any sense?
> The dom0 will only be used to operate the guests - and nothing more. 
> Will this be only placebo security?

Try the attached. I've been running this patch for over a month on
both domU and dom0. paxtest indicates that PaX is working, but I haven't
tried to enable the RBAC system though. The patch was for 2.6.16.29,
but it might apply to a later 2.6.16 kernel. I just haven't tried.

Cheers,

Brad

Attachment: grsec-2.1.9-2.6.16.29-xen-3.0.3.patch.gz
Description: GNU Zip compressed data

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
<Prev in Thread] Current Thread [Next in Thread>