On Saturday, April 8, 2017 at 9:57:26 PM UTC-4, superlative wrote:
> On Saturday, August 29, 2015 at 7:11:41 AM UTC-7, Marek Marczykowski-Górecki 
> wrote:
> > Actually VM template doesn't have anything to say about kernel there. It is
> > provided independently from dom0. If you want some custom kernel (for
> > example grsec patched), you'll need place it in dom0 in
> > /var/lib/qubes/vm-kernels/SOME_NAME/
> > 
> > Some docs, links:
> > 1. Expected files in /var/lib/qubes/vm-kernels/SOME_NAME/: 
> > https://www.qubes-os.org/doc/TemplateImplementation/#modulesimg-xvdd
> > 2. Kernel packaging repo:
> > https://github.com/qubesos/qubes-linux-kernel
> > 3. qubes-prepare-vm-kernel - tool for preparing VM kernel based on one
> > already installed in dom0. Part of `qubes-kernel-vm-support` package
> > (not installed by default).
> > https://github.com/QubesOS/qubes-linux-utils/blob/master/kernel-modules/qubes-prepare-vm-kernel
> > 
> > - -- 
> > Best Regards,
> > Marek Marczykowski-Górecki
> > Invisible Things Lab
> > A: Because it messes up the order in which people normally read text.
> > Q: Why is top-posting such a bad thing?
> 
> Can I please feature request dom0 getting grsecurity patches upstream from 
> Qubes? Coming from someone who tried patching it myself once or twice, I 
> still don't know how to configure the kernel with the new patch. I tried 
> once, and I spent all day picking configurations to match my hardware, and I 
> know I didn't get it all right because there were a lot of acronyms that I 
> didn't understand even after googling them for tens of minutes. However, I 
> just noticed this in the grsecurity instructions that might not have been 
> there last time I tried it myself (I had to contact the developer of 
> grsecurity to update their instructions before on gpg verification which were 
> outdated, I spent enough time googling how to properly use gpg to tell the 
> developer exactly what they needed to change in the instructions which he 
> did), "It is recommended that you start by setting the Configuration Method 
> option to Automatic." Will setting it to automatic mean I won't have to 
> manually configure the hardware, so I can just focus on configuring 
> grsecurity? If so, the grsecurity instructions don't say how to configure 
> grsecurity. So even if I tried doing grsecurity on my own again, I would at 
> least know how to configure (automatically) the hardware, but I still 
> wouldn't know how to configure grsecurity. Or is that automatic too???

there is coldkernel thread on here that uses grsecurity for a vm I think not 
dom0.  That would probably just be an unnecessary nightmare for the developers 
too not just you lol.

Automatic settings,  or for example if you choose security over performance, 
desktop over server.   you have to pick xen obviously.   THere is like 3 or 4 
diff "automatic" settings to choose from.

Grsecurity has default system wide protections which is "automatic" system wide 
protections in the kernel.   then there is something called RBAC, which is like 
a MAC system like Apparmor (which also works in qubes) which also has an 
"automatic" learning mode.  

The part I always had trouble with is that you eventually will have know how to 
edit the rules file manually or add new programs or as system changes or things 
that your automatic profile won't catch.  Most Grsec devs don't even use RBAC I 
guess its something mostly for servers.

For me it was too much trouble for what its worth.  Obviously privilege 
escalation protections are not going to matter.  BUT people forget you can also 
use GRSEC to restrict R00t!

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/6ff0d53c-ca51-4c66-8375-497cdfcd921a%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to