[grsec] grsec + POSIX ACLs

John Logsdon j.logsdon at quantex-research.com
Wed Feb 2 11:25:56 EST 2005


Are there any implications of using POSIX ACLs for example in the /home
directory with grsec?  The latest patch from acl.bestbits.at should be
available shortly for 2.4.29.  In principle they are already in 2.6
kernels but I think it is better to stay with 2.4 for the moment.

join only shows three files where the patches could conflict:

linux-2.4.29/fs/namei.c
linux-2.4.29/kernel/fork.c
linux-2.4.29/kernel/ksyms.c (in 2 places)

apart from the Makefile and Config files of course.

Using both together would give us the best of both worlds - using grsec on
the system and to control the overview but allowing the user to user
g|setfacl on their own directories and files.

TIA

John

John Logsdon                               "Try to make things as simple
Quantex Research Ltd, Manchester UK         as possible but not simpler"
j.logsdon at quantex-research.com              a.einstein at relativity.org
+44(0)161 445 4951/G:+44(0)7717758675       www.quantex-research.com





More information about the grsecurity mailing list