Debian and grsec.

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

Postby puppetm » Fri Dec 13, 2002 6:10 pm

when i start it now i cant login with ssh...

Dec 13 23:11:50 [kernel] grsec: From 127.0.0.1: use of CAP_FOWNER denied for (sshd:28023) UID(0) EUID(0), parent (sshd:25696) UID(0) EUID(0)
puppetm
 
Posts: 11
Joined: Thu Dec 12, 2002 2:59 pm

grsecurity (for 2.4.20)

Postby krupps » Sat Dec 14, 2002 4:46 am

I was not able to start my
XFree86 Version 4.2.1.1 (Debian 4.2.1-4 20021123003806 branden@debian.org) using a brand new and clean kernel 2.4.20 patched with the grsecurity-1.9.8-rc1-2.4.20.patch
and configured with the default setting (HIGH).
My XFree86.log don't shows any error messages (EE).

Switching to the default grsec config. LOW solved the problem.

Now i'm a little bit confused because the official statement seems to be "there is no problem with XFree86 v.4".

What's wrong?

Regards

krupps
krupps
 
Posts: 3
Joined: Sat Dec 14, 2002 4:33 am

in addition some line from kern.log

Postby krupps » Sat Dec 14, 2002 5:11 am

Dec 14 04:43:15 krupps kernel: PAX: terminating task: /usr/X11R6/bin/XFree86(XFree86):14292, uid/euid: 0/0, EIP: 0820FD90, ESP: 5B0502FC
Dec 14 04:43:15 krupps kernel: PAX: bytes at EIP: 55 89 e5 83 ec 08 8b 45 08 a3 00 fe 20 08 83 c4 f4 68 f8 fd
Dec 14 04:43:15 krupps kernel: grsec: attempted resource overstep by requesting 4096 for RLIMIT_CORE against limit 0 by (XFree86:14292) UID(0) EUID(0), parent (gdm:24127) UID(0) EUID(0)
krupps
 
Posts: 3
Joined: Sat Dec 14, 2002 4:33 am

Postby spender » Sat Dec 14, 2002 10:05 am

you need to download http://pageexec.virtualave.net/chpax.c

compile it

chpax -s /usr/X11R6/bin/XFree86
chpax -p /usr/X11R6/bin/XFree86

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm

Re: grsecurity (for 2.4.20)

Postby PaX Team » Sat Dec 14, 2002 6:25 pm

krupps wrote:Switching to the default grsec config. LOW solved the problem.
low turns off PaX (non-executable pages in particular) which makes XFree86 happier. besides using chpax to disable these protections you could also just compile/link a static server and then you can leave all protections enabled on it. i think i posted the details on how to do that somewhere here or on the mailinglist.
PaX Team
 
Posts: 2310
Joined: Mon Mar 18, 2002 4:35 pm

Postby krupps » Sun Dec 15, 2002 2:46 am

Thank you Spender and Pax Team!

Regards

krupps
krupps
 
Posts: 3
Joined: Sat Dec 14, 2002 4:33 am

Postby puppetm » Sun Dec 15, 2002 6:55 am

spender: the loggingfix worked, i got my system up running now, almost got some problems with exim but i am switching to postfix so it dowsnt matter ;)
puppetm
 
Posts: 11
Joined: Thu Dec 12, 2002 2:59 pm

Previous

Return to grsecurity support

cron