Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.kernel > #62931 > unrolled thread

Re: hardening-check can detect whether kernel is protected or not

Started byYves-Alexis Perez <corsac@debian.org>
First post2019-01-02 15:30 +0100
Last post2019-01-02 17:50 +0100
Articles 2 — 1 participant

Back to article view | Back to linux.debian.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: hardening-check can detect whether kernel is protected or not Yves-Alexis Perez <corsac@debian.org> - 2019-01-02 15:30 +0100
    Re: hardening-check can detect whether kernel is protected or not Yves-Alexis Perez <corsac@debian.org> - 2019-01-02 17:50 +0100

#62931 — Re: hardening-check can detect whether kernel is protected or not

FromYves-Alexis Perez <corsac@debian.org>
Date2019-01-02 15:30 +0100
SubjectRe: hardening-check can detect whether kernel is protected or not
Message-ID<xbPGV-7MM-5@gated-at.bofh.it>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Wed, 2019-01-02 at 03:08 +0100, Mikhail Morfikov wrote:
> So does the kernel is protected or not? If yes, why hardening-check can't detect it?
> Also how to get "not stripped" instead of "stripped" kernel?

Hi,

the kernel is not a standard ELF binary, so you can't really run hardening-
check on it and expect sound results.

Yes, the kernel has some protection/hardening (see for example the work done
by the Kernel Self Protection Project).

Regards,
- -- 
Yves-Alexis
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEE8vi34Qgfo83x35gF3rYcyPpXRFsFAlwsyqUACgkQ3rYcyPpX
RFtdiAgAvD9bj/rTlhbHMOkSQQbgoAcpksqIFJQ9HaCMVjDwb6RWc3Dz0IQItJnu
nj2tLZ6An8LJXo5oAoMTCBvBvWGt4/NsedYdVa1Q/610llWJqHg/VfMR4TZaoN8J
0ZWCGD2qwAMx5MZYJ7GQYlXqRpBp+aRvdHd3+DlDo7O+vEKuoQb0bXYolqkgnV4L
UQGgtbCjVfE7V3/pmfBOMBk6ZhpxilLROmFTtL5abtNh81T6P+sOaFKfOjRcufE3
Tmb7qqK9IRJLL48WUtwX5mXyWl/TOTaig23ESfwWOvmCy1pGvh4fERpY9k3W9Y2T
D9iXxQ4nN6yBUu9PXxs76h/IglBEVg==
=ORnQ
-----END PGP SIGNATURE-----

[toc] | [next] | [standalone]


#62937

FromYves-Alexis Perez <corsac@debian.org>
Date2019-01-02 17:50 +0100
Message-ID<xbRSq-BP-19@gated-at.bofh.it>
In reply to#62931
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Wed, 2019-01-02 at 17:37 +0100, Mikhail Morfikov wrote:
> I have one question. Let's say I set the kernel options that are described 
> here[1]. Do I have to use DEB_BUILD_MAINT_OPTIONS or set any additional flags
> in the debian/rules file to get some extra protection? Does the 
> DEB_BUILD_MAINT_OPTIONS variable do something in the case of building the 
> linux kernel?

No, DEB_BUILD_MAINT_OPTIONS is not used for that. If you want to tune the
kernel configuration you need to follow the kernel handbook (
https://kernel-team.pages.debian.net/kernel-handbook/ch-common-tasks.html#s4.2.3
)

Most of the kernel options recommended on the KSPP page are either enabled or
not relevant for a distribution kernel. There are some left which would be
nice to have (like some gcc plugins) and unsupported for now, but that's all.

Regards,
- -- 
Yves-Alexis
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEE8vi34Qgfo83x35gF3rYcyPpXRFsFAlws628ACgkQ3rYcyPpX
RFuq7wgAjwEGti43/zBpdxYSodwujnyh5CGN9k2KDpKtd4UtEJRP9+jWOT3eFuo3
8lKN+nojE7DuxYSJmW9NgXV95DNh1mx191ADRs3brbtV30dSoVP46EfypD/w4rVR
u2QJEEZueQiR7y1qE1nqfhuNY+OTSTlgeYsHbOQ4S5hyn7Yvu3gUf3QXaMOVybnu
+7sbfc62mnXuvwywYU2H891SSjjDd4yf0YUkr1uWWdhWHMvzBulEsj6s8b0QBvWq
DPJAGKd/CUp66R8DVyfY68G7rCam+lrX4DeK3gpPR1npFyIptMdXin64vXRhkaJr
1vZ0ct5r2p8GB0Un7371YEJOIvaQGw==
=1cPi
-----END PGP SIGNATURE-----

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.kernel


csiph-web