Lucas Albers wrote:

I was under the impression that you were not supposed to use gradm with
vservers?


The master server can enable/disable /proc/sys/kernel/grsecurity flags until /proc/sys/kernel/grsecurity/lock is turned on, the chrooted chcontexted processes inside a vps havs no permission to change /proc/sys/kernel/grsecurity flags in any time.
The master server can set ACL policies, the chrooted chcontexted processes inside a vps havs no permission.
Both master and chrooted chcontexted vps can change chpax flags on an elf binary.


Incompatible security format, or something?



-- Sandino Araico S�nchez -- Mel�n se comi� las plumas....

_______________________________________________
Vserver mailing list
[EMAIL PROTECTED]
http://list.linux-vserver.org/mailman/listinfo/vserver

Reply via email to