Gentoo Hardened SELinux policies, rev 5
by Sven Vermeulen, post on Thu 13 October 2011I've pushed out selinux-base-policy
version 2.20110726-r5 to the
hardened-dev
overlay. It does not hold huge changes, most of them are rewrites or
updates on pre-existing patches (on the SELinux policies) to make them
conform the refpolicy naming conventions and other guidelines. It
includes preliminary support for the XDG
Specification …
Upgrading GCC, revisited
by Sven Vermeulen, post on Thu 13 October 2011Gentoo has, since long, had a GCC Upgrading guide. A long time ago, upgrading GCC required quite a lot of side activities and was often considered a risky upgrade. But times change, and so do the GCC upgrade cycles. Improved compatibility as well as a better understood impact made GCC …
Quickly setup a Gentoo system
by Sven Vermeulen, post on Sat 24 September 2011In order to verify if the installation instructions in the Gentoo Handbook are still valid, and to allow me to quickly seed new Gentoo installations in a virtual environment, I wrote a very ugly (really) script to automatically "stage" a Gentoo Linux installation in a KVM guest. This is not …
Power management guide updated
by Sven Vermeulen, post on Fri 23 September 2011The Gentoo Power Management Guide is now updated. It is a full rewrite, focusing currently on two main toolsets: Laptop Mode Tools and cpufreqd. I was pleasantly surprised by the number of features that the laptop mode tools package provided.
Of course, this does not mean that the guide is …
Catching up
by Sven Vermeulen, post on Sun 18 September 2011As mentioned on the gentoo-doc mailinglist, all documentation bugs (that we know of) related to openrc have been fixed. It was already a week like so, but the last dependency on our "tracker" bug was an open one (asking if more needs to be done or not) from which we …
Now using refpolicy 2.20110726
by Sven Vermeulen, post on Sun 04 September 2011A few days ago, I committed the SELinux policy modules that are based on
the 2.20110726 set released upstream. For those that are using Gentoo
Hardened with SELinux, you'll find them if you use the \~arch set for
the sec-policy
category.
When I talk about upstream, it usually is …
Use parted for large partitions
by Sven Vermeulen, post on Wed 24 August 2011A few bugs that were sitting in Gentoo's bugzilla for the documentation were related to large partitions (2 TB and higher). Previously, this wasn't as much as an issue since the number of users that have 2+ TB partitions are fairly slim. But of course time flies, hardware becomes cheaper …
Easy documentation updates thanks to the many contributions
by Sven Vermeulen, post on Mon 22 August 2011As mentioned previously, I took a stab at the Gentoo Guide to OpenLDAP Authentication, updating its configuration settings as well as give an introduction to its replication mechanism. Although I am no OpenLDAP guru at all, I set up a similar architecture for testing some SELinux policy changes. This test …
Ready, set, commit!
by Sven Vermeulen, post on Fri 12 August 2011Yesterday, I have entered the realms of Gentoo Development again. But as it was getting late then, I had to wait before the first commits happened. So this evening, things were done. The first couple of documentation bugs (mostly related to OpenRC) have been committed to the Gentoo CVS repository …
emerge-webrsync and gpg verification
by Sven Vermeulen, post on Fri 22 July 2011Gentoo has been working on its security from very early on. One of the (many) features it supports is to allow users to validate the state of the portage tree. Ebuild signing (where developers sign the Manifest file with their key) is one of the layers offered by Gentoo, but …