I configured grsecurty with the, 1000 is group id for untrusted users.
the system ignores the settings, users from that group still able to execute things around.
below is my kernel config:
http://pastebin.ca/1523213
sysctl -a | grep kernel.grsecurity.tpe