[grsec] virtualisation with grsecurity

John Anderson johnha at ccbill.com
Mon Aug 28 14:21:53 EDT 2006



-----Original Message-----
From: Marcel Meyer [mailto:meyerm at fs.tum.de] 
Sent: Saturday, August 26, 2006 12:40 PM
To: John Anderson
Cc: grsecurity at grsecurity.net
Subject: Re: [grsec] virtualisation with grsecurity


>The concept of xen with a kernel for each domain seems quite nice 
>considering I could use different security settings in each of them.
But 
>the problems with x86 makes me wonder if the combination of xen and 
>grsecurity will be successful in the future and continued to be
developed. 
>Are you currently still active here? Or do you want to wait until xen
hits 
>the kernel tree?

>Thank you for your time,

>Marcel

To be honest now that I have Xen + GRSecurity in a "works for me"
configuration I really don't plan on spending any more time updating it
as Xen updates their code base unless there are major
changes/fixes/enhancements.  However, I do believe that Xen will be a
supported architecture of GRSec/PAX in the future, once it is included
in stable releases of the kernel.org kernel.


More information about the grsecurity mailing list