starting and stopping grsecurity at boot and shutdown

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

starting and stopping grsecurity at boot and shutdown

Postby schmeggahead » Thu Jan 21, 2010 1:20 pm

I have a successful operating grsecurity when the system is active but I have to manually enable it at boot and manually disable it to shutdown.
Is there a facility that I am missing to automatically enable and disable for system startup and shutdown?
(I'm working in the Gentoo distribution using the hardened-sources and profile)

Update: found this related topic on System Shutdown
viewtopic.php?f=3&t=1266&p=9520#p4906
schmeggahead
 
Posts: 5
Joined: Thu Jan 21, 2010 1:09 pm

Re: starting and stopping grsecurity at boot and shutdown

Postby Grach » Tue Jan 26, 2010 10:04 am

To enable RBAC you could run "gradm -E" from any startup script at any time convenient for you, that's simple.

There are several ways to shut down the system with RBAC. For example, you could write permissive rules for /sbin/init and its children (and/or for particular init scripts) as trusted subjects to allow them to shut down the system as usual, without the need to disable RBAC. In this case your RBAC policy must protect /sbin/init (pid 1) from receiving signals from unauthorized subjects and deny them to run /sbin/init (and/or particular init scripts), except the authorized subjects you wish to allow to trigger the system shutdown.
Grach
 
Posts: 66
Joined: Thu Feb 05, 2009 11:15 pm

Re: starting and stopping grsecurity at boot and shutdown

Postby schmeggahead » Wed Jan 27, 2010 7:52 am

I have actually created a new init script for my gentoo system and once gradm is finished enabling, the init script errors all over the place and halts start up.
The RBAC system is enabled and hitting enter allows the system to come up the rest of the way.
This doesn't help me with auto startup.
hmmmm

I guess maybe the pid settings in gentoo aren't needed.
I'll try removing them.
No answer on the gentoo forums about the init script errors.
http://forums.gentoo.org/viewforum-f-18.html
schmeggahead
 
Posts: 5
Joined: Thu Jan 21, 2010 1:09 pm

Re: starting and stopping grsecurity at boot and shutdown

Postby Grach » Wed Jan 27, 2010 10:23 pm

The init scripts fail due to the lack of proper RBAC rules. You should enable the learning mode at boot time and then generate and edit the policy to allow the init scripts to operate. Same for rebooting.
Grach
 
Posts: 66
Joined: Thu Feb 05, 2009 11:15 pm


Return to grsecurity support

cron