Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Security concerns installing hardened gentoo
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
twitch
n00b
n00b


Joined: 10 Aug 2005
Posts: 10

PostPosted: Thu Sep 15, 2005 5:17 pm    Post subject: Security concerns installing hardened gentoo Reply with quote

I have always heard that the most secure way to install a system is to do a networkless install, harden the system, then get the patches/updates.

I am attempting to do that with hardened gentoo, but it isn't going to well for me. I have downloaded the following:
/experimental/x86/hardened/livecd/hardened-x86-2005.1.iso
/experimental/x86/hardened/stages/stage3-x86-selinux-piessp-20050726.tar.bz2

I am attempting to emerge the hardened-sources kernel, but without the network it can't find all of the needed files/packages. I have to go to another machine get the first file it's looking for off the net, copy it over, and then try to emerge again, and the process repeats itself...

So #1, is there an easier way to do this hardened networkless install?

And #2, how large of a security risk is there in doing the network based install?

Thanks,
Steve
Back to top
View user's profile Send private message
nixnut
Bodhisattva
Bodhisattva


Joined: 09 Apr 2004
Posts: 10974
Location: the dutch mountains

PostPosted: Thu Sep 15, 2005 6:04 pm    Post subject: Reply with quote

Could well be that the hardened-sources are not on the hardened livecd. You can build a hardened system, missing only a hardened kernel. You can build a kernel with the pax/grsecurity features later after emerging hardened-sources from the installed system. Since the rest of the system is already hardened and if you're not running al sorts of services (possible points of entry for attackers) the risk of compromise is pretty low.
_________________
Please add [solved] to the initial post's subject line if you feel your problem is resolved. Help answer the unanswered

talk is cheap. supply exceeds demand
Back to top
View user's profile Send private message
Taladar
Guru
Guru


Joined: 09 Oct 2004
Posts: 458
Location: Bielefeld, Germany

PostPosted: Thu Sep 15, 2005 7:29 pm    Post subject: Reply with quote

If you use a router with NAT (and don't forward any ports) the risk is pretty low compared to downloading on another PC (of course should both the Gentoo download mirror and the rsync host with the portage tree be compromised you are screwed anyway).

P.S.: If you worry about the possibility in parentheses you should probably do a full code review of all open source software you use but that is a bit more paranoid than the usual Gentoo Hardened user.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum