Page 1 of 1

splitted patches?

PostPosted: Thu Feb 19, 2004 6:53 pm
by bse
Hi!

I'd like to patch my kernel with only the randomization and chroot features of grsecurity. I don't need the RBAC or MAC features from grsecurity, cause i'm using RSBAC. Can anyone help me on that one?

PostPosted: Sat Feb 21, 2004 1:19 am
by perlish
I thought the RSBAC's jail module are more powerful than chroot

it seens that the rsbac do not have learning mode

I'd like grsec's acl

but if the grsec has the bsdjail function it may be PERFECT!!!

PostPosted: Sat Feb 21, 2004 5:05 am
by bse
Yes it has a JAIL module, but if u're a little paranoid, some extra protection may be good ;)

And still it doesn't have the randomization features.

PostPosted: Sun Feb 22, 2004 11:08 am
by magicq
if u have used the freebsd's jail function ,I thought u also will show interesting in it

if u only need random function ,u can use PAX with rsbac,and use the rsbac's jail function instead of chroot