From df1b0c97be81b3a7e9387484d5047e5aea0680d5 Mon Sep 17 00:00:00 2001 From: Benjamin Kaduk Date: Tue, 19 Jan 2016 02:41:44 +0000 Subject: [PATCH] Add HardenedBSD entry from Shawn Webb --- .../news/status/report-2015-10-2015-12.xml | 85 +++++++++++++++++++ 1 file changed, 85 insertions(+) diff --git a/en_US.ISO8859-1/htdocs/news/status/report-2015-10-2015-12.xml b/en_US.ISO8859-1/htdocs/news/status/report-2015-10-2015-12.xml index a646b493cd..94bc358f61 100644 --- a/en_US.ISO8859-1/htdocs/news/status/report-2015-10-2015-12.xml +++ b/en_US.ISO8859-1/htdocs/news/status/report-2015-10-2015-12.xml @@ -4282,4 +4282,89 @@ + + + HardenedBSD + + + + + Shawn + Webb + + shawn.webb@hardenedbsd.org + + + + + Oliver + Pinter + + oliver.pinter@hardenedbsd.org + + + + + + Introducing HardenedBSD's New Binary Updater + secadm Beta Published + New Package Building Server + secadm + HardenedBSD Haswell Support + Nightly Builds for HardenedBSD Haswell Support + + + +

HardenedBSD has been hard at work improving the + performance and stability of our security enhancements. Security + flags are now per-thread instead of per-process, removing some + locking overhead. ASLR for mmap(MAP_32BIT) requests has been + refactored, but lib32 is now disabled by default.

+ +

We've developed a new binary update utility, + hbsd-update akin to freebsd-update. + In addition to normal OS installs, it can also update + jails and ZFS Boot Environments (ZFS BEs). Updates are + signed using X.509 certificates.

+ +

secadm 0.3-beta has landed. It has been + rewritten from scratch in order to be more efficient. As part of + the rewrite, the rule syntax has changed and users must update + their rulesets as described in the README.

+ +

Thanks to generous donations of a server from G2, Inc and + hosting from Automated Tendencies, we can now do full + package builds in just 35 hours, down from 75 hours. + This machine will also provide weekly binary updates for + the kernel and base system.

+ +

Owing partly to the needs of the developers, we have + an experimental branch that includes the work + &a.dumbbell; has underway for Haswell graphics support, + on top of &os; 11-current. Binary updates are also + provided for this branch.

+ +

Unfortunately, in order to focus our efforts on improving + HardenedBSD, we have had to pull back from submitting our ASLR + patches to &os;. The past two years' efforts to address comments + on the submission have taken their toll, and the effort is no + longer sustainable. We are proud to be based on &os; and believe + that the whole community could benefit from the security + technologies we are developing. We hope that someone else will + be able to step forward and finish off the task of integrating + ASLR into &os;.

+ + + + Automated Tendencies + + + + G2, Inc + + + + SoldierX + +