Well, I'm not sure, but I do not run a hardened php, if that's what you
mean. I have a gentoo hardened selinux server. On wich I am installing
php5 to run phpldapadmin. So I can add sasl authentication support to it
and use it as a secure admin client. So it stil would be a normal php,
running in a specific SELinux context.
But you could consider using the ebuild anyway, because I know gentoo
for beinig very flexible. You could for example run the download part of
the ebuild, configure it manualy and then continue the ebuild. Or you
could adapt the existing ebuild to your specific needs.
Albert Lash wrote:
Can you share your technique? I'm contemplating switching to emerging php
from compiling my own binary. I'm going through the file contexts for my
own layout and setup and its laborious. Having my own way is not
necessarily worth it if there is a hardened version that is
semi-pre-configured.
Thanks,
Albert
On Tue, 27 Sep 2005, Mivz wrote:
I found it. They organized it. Great, much better this way!
Nate Seif wrote:
I believe that there is a php5 ebuild in the Hardened Portage tree
under dev-lang/php. (Recently the PHP ebuilds have been moved around a
bit.) Update your portage tree and try emerging dev-lang/php. The
latest version in Portage (5.0.5) might be masked so unmask it by
adding a line like "dev-lang/php ~x86" to /etc/portage/package.keywords.
Check out
http://svn.gnqs.org/projects/gentoo-php-overlay/file/docs/php-upgrading.html?format=raw
for info on installing PHP5.
Nate
Mivz wrote:
I am working on a LDAPv3 project for my graduation. It runs on a
hardened-selinux server. I want to implement sasl authentication on
phpldapadmin for this, to have a grafical, secure, admin tool.
The problem is, there is no php5 ebuild in the hardend portage tree.
This is kind of a problem, cause sasl authentication is only
supported in php5.
Is there a specific reason php5 is not in the hardend portage tree?
And could I use the ebuild of the normal portage tree and write a
php5 policy myself to do this?
Mivz, Spugium
--
[email protected] mailing list
--
[email protected] mailing list