Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Page 1 of 2 1 2 LastLast
Results 1 to 15 of 19
  1. #1
    cPanel Partner NOC This forum account has been confirmed by cPanel staff to represent a vendor.cPanel Partner NOC Badge
    Join Date
    Nov 2001
    Location
    San Clemente, Ca
    Posts
    703

    Default RH9 Kernel RPM with grsecurity (beta testers).

    I have build a Redhat 9 kernel with the grsecurity patch applied. I am looking for admins who wish to test this kernel. If you wish to test it, you can download it by clicking the link below. I would like feedback about how the install went and what type of hardware config you have. Send feedback to feedback@ndchost.com

    http://www.cplicensing.net/new/grsecurity.php


    btw, i have tested it on 2 machines.
    Shaun Reitan
    NDCHost.com - cPlicensing.net - ProVPS.com
    Contact us for your cPanel Licensing needs! We Price Match, We provide Support, We take care of our customers!

  2. #2
    Member
    Join Date
    Aug 2002
    Posts
    1,052

    Default

    I won't use the RPMs, but it might be good to include what options you checked off in grsecurity. People who are familiar with grsec know that it has a myriad of options.

    The rest of those who have gone before us cannot steady the unrest of those to follow.

  3. #3
    Member
    Join Date
    Oct 2003
    Posts
    10

    Default

    Also, I think it would be a nice project of some type if someone could develop some very strict ACLs for grsec that are compatible with cpanel.

  4. #4
    cPanel Partner NOC This forum account has been confirmed by cPanel staff to represent a vendor.cPanel Partner NOC Badge
    Join Date
    Nov 2001
    Location
    San Clemente, Ca
    Posts
    703

    Default

    ciphervendor: Your right, thats a very important part that people need to know about. The option used was medium.


    I'd like to see a strict ACL for cPanel box's as well. i may try playing with learn mode when i have some time.
    Shaun Reitan
    NDCHost.com - cPlicensing.net - ProVPS.com
    Contact us for your cPanel Licensing needs! We Price Match, We provide Support, We take care of our customers!

  5. #5
    DHL
    DHL is offline
    Member
    Join Date
    Mar 2002
    Posts
    88

    Default

    Im using grsec on high security with cpanel on around 25 boxes, no problems, gradm and strict acls are definitely to be tested on a spare server first

    Still learning that one myself.

  6. #6
    cPanel Partner NOC This forum account has been confirmed by cPanel staff to represent a vendor.cPanel Partner NOC Badge
    Join Date
    Nov 2001
    Location
    San Clemente, Ca
    Posts
    703

    Default

    DHL,

    I heard high was too strict for a cPanel box. If this isnt the case i will build the rpms with as high.
    Shaun Reitan
    NDCHost.com - cPlicensing.net - ProVPS.com
    Contact us for your cPanel Licensing needs! We Price Match, We provide Support, We take care of our customers!

  7. #7
    DHL
    DHL is offline
    Member
    Join Date
    Mar 2002
    Posts
    88

    Default

    Hi Shaun,

    No problems with high security and cpanel - Ive been running grsec with high security on servers since last November without issue - Theres a monitoring server in your dc with rh9 and grsec on high if you want to look into it

  8. #8
    Member
    Join Date
    Oct 2003
    Posts
    10

    Default

    I would net recommend just setting it to "high". Go through the options and customize the configuration of grsecurity.

  9. #9
    cPanel Partner NOC This forum account has been confirmed by cPanel staff to represent a vendor.cPanel Partner NOC Badge
    Join Date
    Nov 2001
    Location
    San Clemente, Ca
    Posts
    703

    Default

    revision 0.3 has grsecuity set to high for those who want to test.

    http://www.cplicensing.net/new/grsecurity.php
    Shaun Reitan
    NDCHost.com - cPlicensing.net - ProVPS.com
    Contact us for your cPanel Licensing needs! We Price Match, We provide Support, We take care of our customers!

  10. #10
    DHL
    DHL is offline
    Member
    Join Date
    Mar 2002
    Posts
    88

    Default

    The rpms work well shaun, tested on i686 and athlons and no problems to report.

    For folks that don't feel comfortable with compiling their own kernels (or want to avoid the odd mishap I highly recommend these kernels.

    If you are running Tomkat, do not go for the high security option as grsec does not like that.

    The kernels are a great idea, nice to have someone doing these things volountary for the folks around here - kudos.

  11. #11
    cPanel Partner NOC This forum account has been confirmed by cPanel staff to represent a vendor.cPanel Partner NOC Badge
    Join Date
    Nov 2001
    Location
    San Clemente, Ca
    Posts
    703

    Default

    Maybe i'll buld a set of them, low, medium, and high.

    The build process takes forever... even on a p4 2.4GHZ with 1GB ram.
    Shaun Reitan
    NDCHost.com - cPlicensing.net - ProVPS.com
    Contact us for your cPanel Licensing needs! We Price Match, We provide Support, We take care of our customers!

  12. #12
    Member
    Join Date
    Aug 2002
    Posts
    1,052

    Default

    For tomcat you simply need to download the chpax code from the pax site and flag the tomcat binaries--if you want to use the grsec high settings.

    The rest of those who have gone before us cannot steady the unrest of those to follow.

  13. #13
    DHL
    DHL is offline
    Member
    Join Date
    Mar 2002
    Posts
    88

    Default

    Originally posted by ciphervendor
    For tomcat you simply need to download the chpax code from the pax site and flag the tomcat binaries--if you want to use the grsec high settings.
    Nice tip, just saying that regarding tomcat as anyone who is installing the rpms probably won't know how or want to go into too many details regarding pax and acls and it will break tomcat otherwise.

  14. #14
    Member
    Join Date
    Dec 2002
    Posts
    57

    Default

    any new version of the custom kernels?

  15. #15
    cPanel Partner NOC This forum account has been confirmed by cPanel staff to represent a vendor.cPanel Partner NOC Badge
    Join Date
    Nov 2001
    Location
    San Clemente, Ca
    Posts
    703

    Default

    i have yet to build a new grsec kernel, it's not as easy as you'd think as i have to pull all the config changes and i have yet to find a easy way to do that. When grsec releases a patch for the kernel that just came out, i'll see if i can get a new version up.
    Shaun Reitan
    NDCHost.com - cPlicensing.net - ProVPS.com
    Contact us for your cPanel Licensing needs! We Price Match, We provide Support, We take care of our customers!

Similar Threads & Tags
Similar threads
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube