Does Qubes Use GrSecurity?

409 views
Skip to first unread message

jonbrown...@gmail.com

unread,
Aug 28, 2015, 11:31:30 PM8/28/15
to qubes-users
Does Qubes OS take advantage of GrSecurity security enhancements? Maybe Dom0 or any others? I know its supposed to provide huge advantages to the kernel out of the box and unfortunately almost no distros use it.

Thanks

https://grsecurity.net/

7v5w7go9ub0o

unread,
Aug 29, 2015, 9:52:48 AM8/29/15
to qubes...@googlegroups.com
I believe the answer for Fedora remains no. But the developers are
aware of GRS.

IMHO, the real advantage of GRS would not be in DOM0 which is well
insulated by XEN and the OS design, but in a template VM which is the
basis for NetVM, Firewall, DispVM, etc.

GRS is readily configurable and could be modestly configured to provide
some significant improvements using provided utilities.

I'd guess a good next step for you is to review the available templates
<https://www.qubes-os.org/doc/Templates/> and look for a distribution
that provides a GRS-patched, compiled kernel - compatible with Qubes (I
don't know what this is; I note only that some kernels have issues with
Qubes) - as a distribution option.




Marek Marczykowski-Górecki

unread,
Aug 29, 2015, 10:11:41 AM8/29/15
to 7v5w7go9ub0o, qubes...@googlegroups.com, jonbrown...@gmail.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Actually VM template doesn't have anything to say about kernel there. It is
provided independently from dom0. If you want some custom kernel (for
example grsec patched), you'll need place it in dom0 in
/var/lib/qubes/vm-kernels/SOME_NAME/

Some docs, links:
1. Expected files in /var/lib/qubes/vm-kernels/SOME_NAME/:
https://www.qubes-os.org/doc/TemplateImplementation/#modulesimg-xvdd
2. Kernel packaging repo:
https://github.com/qubesos/qubes-linux-kernel
3. qubes-prepare-vm-kernel - tool for preparing VM kernel based on one
already installed in dom0. Part of `qubes-kernel-vm-support` package
(not installed by default).
https://github.com/QubesOS/qubes-linux-utils/blob/master/kernel-modules/qubes-prepare-vm-kernel

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQEcBAEBCAAGBQJV4b2VAAoJENuP0xzK19csS1wH/RizY3lYWsllahGf2UV4iybY
DnGHr7ODICzHmXkRMmR5tE4PAii//fcFOiYJtQYNTxtIIRMILkkxWcu4pqHrwwD6
TlHOFnUidXBsjE9yZxSzViEdxb+QDgJfNUtj1INL1/O2G+1Br7aboTn+1BV3EUAH
FPOpbRUCHWsL0eZPJhWwN9R3pMVsy5dtYGBiw9+ow6LZ/PwtRS04Kso9KkIMXpaa
ufaOhW+B1TA5iNGnMapHYoAQvrD0xtRDBeyese+pMTsgHnJc8AMN5zfTxpAn2zL7
67PBAJi10OSBctPXzEgPPBL/s0wxtaUdHRJ7NbWYa+jsmLp4fVaTOKB5EOJBX0s=
=oC8c
-----END PGP SIGNATURE-----

7v5w7go9ub0o

unread,
Aug 29, 2015, 10:31:08 AM8/29/15
to qubes...@googlegroups.com
AH!

Thanks for the corrections, and the very quick/informative response!!


superlative

unread,
Apr 8, 2017, 9:57:26 PM4/8/17
to qubes-users, 7v5w7g...@gmail.com, jonbrown...@gmail.com
On Saturday, August 29, 2015 at 7:11:41 AM UTC-7, Marek Marczykowski-Górecki wrote:
> Actually VM template doesn't have anything to say about kernel there. It is
> provided independently from dom0. If you want some custom kernel (for
> example grsec patched), you'll need place it in dom0 in
> /var/lib/qubes/vm-kernels/SOME_NAME/
>
> Some docs, links:
> 1. Expected files in /var/lib/qubes/vm-kernels/SOME_NAME/:
> https://www.qubes-os.org/doc/TemplateImplementation/#modulesimg-xvdd
> 2. Kernel packaging repo:
> https://github.com/qubesos/qubes-linux-kernel
> 3. qubes-prepare-vm-kernel - tool for preparing VM kernel based on one
> already installed in dom0. Part of `qubes-kernel-vm-support` package
> (not installed by default).
> https://github.com/QubesOS/qubes-linux-utils/blob/master/kernel-modules/qubes-prepare-vm-kernel
>
> - --
> Best Regards,
> Marek Marczykowski-Górecki
> Invisible Things Lab
> A: Because it messes up the order in which people normally read text.
> Q: Why is top-posting such a bad thing?

Can I please feature request dom0 getting grsecurity patches upstream from Qubes? Coming from someone who tried patching it myself once or twice, I still don't know how to configure the kernel with the new patch. I tried once, and I spent all day picking configurations to match my hardware, and I know I didn't get it all right because there were a lot of acronyms that I didn't understand even after googling them for tens of minutes. However, I just noticed this in the grsecurity instructions that might not have been there last time I tried it myself (I had to contact the developer of grsecurity to update their instructions before on gpg verification which were outdated, I spent enough time googling how to properly use gpg to tell the developer exactly what they needed to change in the instructions which he did), "It is recommended that you start by setting the Configuration Method option to Automatic." Will setting it to automatic mean I won't have to manually configure the hardware, so I can just focus on configuring grsecurity? If so, the grsecurity instructions don't say how to configure grsecurity. So even if I tried doing grsecurity on my own again, I would at least know how to configure (automatically) the hardware, but I still wouldn't know how to configure grsecurity. Or is that automatic too???

cooloutac

unread,
Apr 8, 2017, 10:33:09 PM4/8/17
to qubes-users, 7v5w7g...@gmail.com, jonbrown...@gmail.com
there is coldkernel thread on here that uses grsecurity for a vm I think not dom0. That would probably just be an unnecessary nightmare for the developers too not just you lol.

Automatic settings, or for example if you choose security over performance, desktop over server. you have to pick xen obviously. THere is like 3 or 4 diff "automatic" settings to choose from.

Grsecurity has default system wide protections which is "automatic" system wide protections in the kernel. then there is something called RBAC, which is like a MAC system like Apparmor (which also works in qubes) which also has an "automatic" learning mode.

The part I always had trouble with is that you eventually will have know how to edit the rules file manually or add new programs or as system changes or things that your automatic profile won't catch. Most Grsec devs don't even use RBAC I guess its something mostly for servers.

For me it was too much trouble for what its worth. Obviously privilege escalation protections are not going to matter. BUT people forget you can also use GRSEC to restrict R00t!
Reply all
Reply to author
Forward
0 new messages