Kernel security advice


* Besides grsecurity patch, pax etc...What other recommendations are there
to patch a kernel on a woody or sarge production server?

* Any experiences/opinions with the debian-hardened kernels?

* Is it that terrible running X if access is not allowed from the network,
only locally?


-JM.

