aboutsummaryrefslogtreecommitdiff
path: root/research/hardened.md
diff options
context:
space:
mode:
authorSilvio Rhatto <rhatto@riseup.net>2021-01-17 14:32:44 -0300
committerSilvio Rhatto <rhatto@riseup.net>2021-01-17 14:32:44 -0300
commit7f52a0acea5d766c0c25997df1dd907162db0407 (patch)
tree8341ccdd319c5a0d18123ff0ad5f3e2d53dcd61e /research/hardened.md
parentde236e0e54d1cc4ba1cac5d687e3c3112fded44e (diff)
downloadblog-7f52a0acea5d766c0c25997df1dd907162db0407.tar.gz
blog-7f52a0acea5d766c0c25997df1dd907162db0407.tar.bz2
Fix: remove old, incomplete research
Diffstat (limited to 'research/hardened.md')
-rw-r--r--research/hardened.md44
1 files changed, 0 insertions, 44 deletions
diff --git a/research/hardened.md b/research/hardened.md
deleted file mode 100644
index f59a43e..0000000
--- a/research/hardened.md
+++ /dev/null
@@ -1,44 +0,0 @@
-[[!meta title="Hardened OS"]]
-[[!tag research hardened grsecurity security]]
-
-grsecurity
-----------
-
-Basic install:
-
- sudo apt-get -t jessie-backports install linux-image-4.9.0-2-grsec-amd64 linux-image-grsec-amd64
- sudo apt-get install paxtest
- sudo usermod -aG grsec-tpe `whoami`
-
-As root:
-
- echo "kernel.grsecurity.rwxmap_logging = 0" > /etc/sysctl.d/kernel.grsecurity.rwxmap_logging.conf
- echo "kernel.grsecurity.grsec_lock = 1" > /etc/sysctl.d/kernel.grsecurity.grsec_lock.conf
-
-As regular user, after reboot:
-
- paxctl -cm /usr/bin/git-annex
- paxctl -cm /usr/bin/qemu-img
- paxctl -cm /usr/bin/qemu-system-x86_64
-
-Further research
-----------------
-
-LXC unprivileged containers for GUI applications:
-
-* [LXC 1.0: GUI in containers [9/10] | Stéphane Graber's website](https://stgraber.org/2014/02/09/lxc-1-0-gui-in-containers/).
-* [Configuring Unprivileged LXC containers in Debian Jessie](https://myles.sh/configuring-lxc-unprivileged-containers-in-debian-jessie/).
-* [LXC - Debian Wiki](https://wiki.debian.org/LXC).
-
-References
-----------
-
-* https://micahflee.com/2016/01/debian-grsecurity/
-* https://nixaid.com/grsec-in-docker/
-* https://hardenedlinux.github.io/
-* https://packages.debian.org/stretch/bubblewrap
-* https://packages.debian.org/stretch/runc
-* https://github.com/projectatomic/bubblewrap
-* https://github.com/opencontainers/runc
-* https://github.com/thestinger/playpen
-* https://github.com/omegaup/minijail