Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 138453 - Request for openswan/shorewall support in hardened kernel
Summary: Request for openswan/shorewall support in hardened kernel
Status: RESOLVED INVALID
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Hardened (show other bugs)
Hardware: All Linux
: High enhancement (vote)
Assignee: The Gentoo Linux Hardened Team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-06-29 04:20 UTC by Natanael Copa
Modified: 2006-07-01 10:36 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Natanael Copa 2006-06-29 04:20:41 UTC
I just discovered that i won't get my hardened gentoo kernel work with openswan/shorewall out of the box. There are a few patches that are missing, for example policy match.

There is a list at the top of this document:
http://www.shorewall.net/IPSEC-2.6.html

And this howto shows also what how to patch the kernel to get openswan/shorewall work:
http://gentoo-wiki.com/HOWTO_Shorewall_Firewall_IPsec_VPN_and_2.6_kernel

It would be great if the missing patches were included in the gentoo hardened kernel. (and iptables too ofcourse)

Thanks!
Comment 1 Kevin F. Quinn (RETIRED) gentoo-dev 2006-06-29 05:18:37 UTC
from http://gentoo-wiki.com/HOWTO_Shorewall_Firewall_IPsec_VPN_and_2.6_kernel:

"Update: As of kernel 2.6.16, policy match support is built-in. No patching needed (tested with gentoo-sources-2.6.16-r1, iptables-1.3.5 + extensions USE flag, ipsec-tools-0.6.2-r1 on ~x86). Just follow this guide until the first emerge instruction in "Get the software" section (if necessary, add sys-kernel/gentoo-sources to /etc/portage/package.keywords), then jump to "Recompile your kernel" and finally jump down to "Test Shorewall"."

so just try the 2.6.16 hardened sources, and it looks like the other tools also have the relevant support.

So nothing to fix :)
Comment 2 Natanael Copa 2006-06-29 05:25:24 UTC
So what I actually wanted was to get 2.6.16 marked stable, since it also fixes #137061

thanks!
Comment 3 solar (RETIRED) gentoo-dev 2006-06-29 06:16:43 UTC
.16 probably wont be marked stable unless the grsec/pax patches come 
out of http://grsecurity.net/~spender/ and find themselves here 
http://grsecurity.net/download.php ; 

Perhaps you could/should start a thread on the grsec ml and find out 
whats the status..
Comment 4 Natanael Copa 2006-07-01 10:36:56 UTC
(In reply to comment #3)
> .16 probably wont be marked stable unless the grsec/pax patches come 
> out of http://grsecurity.net/~spender/ and find themselves here 
> http://grsecurity.net/download.php ; 
> 
> Perhaps you could/should start a thread on the grsec ml and find out 
> whats the status..

I joined list and posted message. List is moderated and my message has still not been accepted. Look slike nothing have been accepted since May.