latest kernel-secure package have preconfigured options about grsecurity patch. previous kernels hasn't this variable set, admin can set these variables and tune grsec module by hand via sysctl interface.
unfortunatelly, one of preset variables is kernel.grsecurity.grsec_lock which is set to 1. this mean, that no changes in grsecurity parameters is enabled :( i think, that old way is better and give admins better control, then i requested remove all preconfigured variables about grsecurity and keep it in "0". thanks
pgp00000.pgp
Description: PGP signature
