[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: harden distribution



On Fri, Jun 29, 2001 at 07:25:21PM +0200, Jan-Hendrik Palic wrote:
> On Thu, Jun 28, 2001 at 06:22:43PM +0200, David Spreen wrote:
> > What I mean is a distribution in which every programm is compiled
> > using stackguard. Some security related systems, like lids and so
> > on. The problem is, hey, of course we can recompile all the
> > programms and make a -sg version of all our packages, but themn
> > the distribution becomes too complex I think.
> 
> Do you maen, we should have tgo versions of the packages, one is
> normal and one is the secure one?
> 
> We can't recompile all these packages, that's true.

I agree. Fortunately, the solution is simple: Extend the package
system to make auto-building of packages as simple and automatic as
installation of binary packages.

This would allow not only for compilation using things such as
StackGuard, but also for optimization for newer x86 processors,
packages with /usr/doc removed etc etc...

IMHO, both Stackguard binaries and optimized binaries fall under
"special needs", additionally we simply cannot provide all
*combinations* of these features as well - this justifies that
installation of such a package takes a little more resources (because
the compilation takes place on the user's machine).

Cheers,

  Richard

-- 
  __   _
  |_) /|  Richard Atterer     |  CS student at the Technische  |  GnuPG key:
  | \/¯|  http://atterer.net  |  Universität München, Germany  |  0x888354F7
  ¯ ´` ¯

Attachment: pgpvnkkdVYkIz.pgp
Description: PGP signature


Reply to: