Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Wed Nov 03, 2010 1:56 am 
Offline
Senior Newbie

Joined: Wed Nov 03, 2010 1:50 am
Posts: 12
# lidsadm -I
INIT
open: No such file or directory
lidsadm: cannot open /sys/kernel/security/lids/locks
reason:: No such file or directory



Whats happening?


Top
   
 Post subject:
PostPosted: Wed Nov 03, 2010 6:18 am 
Offline
Senior Member
User avatar

Joined: Sat Aug 30, 2008 1:55 pm
Posts: 1739
Location: Rochester, New York
It looks like lids requires patches to the kernel. I can't find a package with lidsadm in Debian (nor anything with "lids" in its name), so I don't know if there's a Debian kernel with the hacks or if you'll need to roll your own. Both possibilities are covered by these articles.

_________________
Code:
/* TODO: need to add signature to posts */


Top
   
 Post subject:
PostPosted: Wed Nov 03, 2010 9:47 am 
Offline
Senior Newbie

Joined: Wed Nov 03, 2010 1:50 am
Posts: 12
I've patched the kernel source,compiled and installed it.


Top
   
 Post subject:
PostPosted: Wed Nov 03, 2010 10:12 am 
Offline
Senior Member
User avatar

Joined: Tue May 26, 2009 3:29 pm
Posts: 1691
Location: Montreal, QC
decbin wrote:
I've patched the kernel source,compiled and installed it.


Are you sure that you're running it? You selected pvgrub in the linode manager and confirmed that you're running your custom-compiled kernel? Merely installing the kernel is insufficient.


Top
   
 Post subject:
PostPosted: Wed Nov 03, 2010 10:21 am 
Offline
Senior Newbie

Joined: Wed Nov 03, 2010 1:50 am
Posts: 12
Guspaz wrote:
decbin wrote:
I've patched the kernel source,compiled and installed it.


Are you sure that you're running it? You selected pvgrub in the linode manager and confirmed that you're running your custom-compiled kernel? Merely installing the kernel is insufficient.



Yes,also used "uname -a" to confirm.

I like Debian,but it seems that LIDS don't,LOL.


Top
   
 Post subject:
PostPosted: Wed Nov 03, 2010 11:35 am 
Offline
Senior Member
User avatar

Joined: Tue Nov 24, 2009 1:59 pm
Posts: 362
zgrep -i lids /proc/config.gz
dmesg | grep -i lids

You sure you have compiled it statically and not as a module (or
have it specified in /etc/modules)?

_________________
rsk, providing useless advice on the Internet since 2005.


Top
   
 Post subject:
PostPosted: Wed Nov 03, 2010 11:41 am 
Offline
Senior Newbie

Joined: Wed Nov 03, 2010 1:50 am
Posts: 12
rsk wrote:
zgrep -i lids /proc/config.gz
dmesg | grep -i lids

You sure you have compiled it statically and not as a module (or
have it specified in /etc/modules)?



# zgrep -i lids /proc/config.gz
CONFIG_LIDS=y
CONFIG_LIDS_NO_FLOOD_LOG=y
CONFIG_LIDS_ALLOW_SWITCH=y
CONFIG_LIDS_ALLOW_LFS=y
CONFIG_LIDS_RESTRICT_MODE_SWITCH=y
CONFIG_LIDS_MODE_SWITCH_CONSOLE=y
CONFIG_LIDS_MODE_SWITCH_SERIAL=y
CONFIG_LIDS_MODE_SWITCH_PTY=y
CONFIG_LIDS_NF_MARK=y
CONFIG_LIDS_TPE=y
CONFIG_LIDS_TDE=y
CONFIG_CAP_LIDS_SANDBOX_EFF_SET=y
CONFIG_LIDS_SHRINK_SIZE=y
CONFIG_LIDS_DEBUG=y






# dmesg | grep -i lids
LIDS: Initializing...
Failure registering LIDS with the kernel


Top
   
 Post subject:
PostPosted: Wed Nov 03, 2010 1:02 pm 
Offline
Senior Member
User avatar

Joined: Tue Nov 24, 2009 1:59 pm
Posts: 362
decbin wrote:
# dmesg | grep -i lids
LIDS: Initializing...
Failure registering LIDS with the kernel

This sure sounds bad... you sure the patch is meant for thie kernel version, that you have all the prereqs if any (does LIDS depend on grsec? Sorry, I don't use any of these hardening stuffs...)...

Got the basic security framework and securityfs enabled? Do you have any install docs there, and did you read them? (can't find a thing on their website... >.<)

_________________
rsk, providing useless advice on the Internet since 2005.


Top
   
 Post subject:
PostPosted: Wed Nov 03, 2010 1:22 pm 
Offline
Senior Newbie

Joined: Wed Nov 03, 2010 1:50 am
Posts: 12
rsk wrote:
decbin wrote:
# dmesg | grep -i lids
LIDS: Initializing...
Failure registering LIDS with the kernel

This sure sounds bad... you sure the patch is meant for thie kernel version, that you have all the prereqs if any (does LIDS depend on grsec? Sorry, I don't use any of these hardening stuffs...)...

Got the basic security framework and securityfs enabled? Do you have any install docs there, and did you read them? (can't find a thing on their website... >.<)




Yes.I googled but found no solution.


Top
   
 Post subject:
PostPosted: Wed Nov 03, 2010 2:16 pm 
Offline
Senior Member
User avatar

Joined: Tue Nov 24, 2009 1:59 pm
Posts: 362
Okay, okay.
dmesg | grep -A15 'LIDS:.*Initializing'
There may be lines without LIDS prefix between the initialize and the failure message....

_________________
rsk, providing useless advice on the Internet since 2005.


Top
   
 Post subject:
PostPosted: Wed Nov 03, 2010 2:20 pm 
Offline
Senior Member
User avatar

Joined: Fri Dec 11, 2009 7:09 pm
Posts: 168
This is above my pay grade, but all of the Google hits I found were quite old, but they all specified the need to use a vanilla kernel, and that the lids patch wouldn't work if other hardening patches were installed.

_________________
--
Chris Bryant


Top
   
 Post subject:
PostPosted: Wed Nov 03, 2010 2:31 pm 
Offline
Senior Newbie

Joined: Wed Nov 03, 2010 1:50 am
Posts: 12
Thanks to everyone who replys this topic.



:/usr/src/linux# dmesg | grep -A15 'LIDS:.*Initializing'
LIDS: Initializing...
Failure registering LIDS with the kernel
Mount-cache hash table entries: 512
CPU: L1 I cache: 32K, L1 D cache: 32K
CPU: L2 cache: 256K
CPU: L3 cache: 8192K
CPU: Unsupported number of siblings 16
Performance Events: unsupported p6 CPU model 26 no PMU driver, software events only.
Freeing SMP alternatives: 25k freed
cpu 0 spinlock event irq 1
installing Xen timer for CPU 1
cpu 1 spinlock event irq 7
Initializing CPU#1
CPU: L1 I cache: 32K, L1 D cache: 32K
CPU: L2 cache: 256K
CPU: L3 cache: 8192K


Top
   
 Post subject:
PostPosted: Wed Nov 03, 2010 3:11 pm 
Offline
Senior Member
User avatar

Joined: Tue Nov 24, 2009 1:59 pm
Posts: 362
Yeah, well... no additional info between the two linds-related lines... Tried asking in LIDS-related mailing lists?

_________________
rsk, providing useless advice on the Internet since 2005.


Top
   
 Post subject:
PostPosted: Fri Nov 05, 2010 12:36 am 
Offline
Senior Newbie

Joined: Wed Nov 03, 2010 1:50 am
Posts: 12
OK,let me try,thanks a lot.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group