From owner-svn-doc-head@freebsd.org Tue Jan 19 02:41:46 2016 Return-Path: Delivered-To: svn-doc-head@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 2A615A872F2; Tue, 19 Jan 2016 02:41:46 +0000 (UTC) (envelope-from bjk@FreeBSD.org) Received: from repo.freebsd.org (repo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 071BB1B0C; Tue, 19 Jan 2016 02:41:45 +0000 (UTC) (envelope-from bjk@FreeBSD.org) Received: from repo.freebsd.org ([127.0.1.37]) by repo.freebsd.org (8.15.2/8.15.2) with ESMTP id u0J2fjgU004558; Tue, 19 Jan 2016 02:41:45 GMT (envelope-from bjk@FreeBSD.org) Received: (from bjk@localhost) by repo.freebsd.org (8.15.2/8.15.2/Submit) id u0J2fjk0004557; Tue, 19 Jan 2016 02:41:45 GMT (envelope-from bjk@FreeBSD.org) Message-Id: <201601190241.u0J2fjk0004557@repo.freebsd.org> X-Authentication-Warning: repo.freebsd.org: bjk set sender to bjk@FreeBSD.org using -f From: Benjamin Kaduk Date: Tue, 19 Jan 2016 02:41:45 +0000 (UTC) To: doc-committers@freebsd.org, svn-doc-all@freebsd.org, svn-doc-head@freebsd.org Subject: svn commit: r48064 - head/en_US.ISO8859-1/htdocs/news/status X-SVN-Group: doc-head MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-BeenThere: svn-doc-head@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: SVN commit messages for the doc tree for head List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 19 Jan 2016 02:41:46 -0000 Author: bjk Date: Tue Jan 19 02:41:44 2016 New Revision: 48064 URL: https://svnweb.freebsd.org/changeset/doc/48064 Log: Add HardenedBSD entry from Shawn Webb Modified: head/en_US.ISO8859-1/htdocs/news/status/report-2015-10-2015-12.xml Modified: head/en_US.ISO8859-1/htdocs/news/status/report-2015-10-2015-12.xml ============================================================================== --- head/en_US.ISO8859-1/htdocs/news/status/report-2015-10-2015-12.xml Tue Jan 19 02:28:43 2016 (r48063) +++ head/en_US.ISO8859-1/htdocs/news/status/report-2015-10-2015-12.xml Tue Jan 19 02:41:44 2016 (r48064) @@ -4282,4 +4282,89 @@ + + + HardenedBSD + + + + + Shawn + Webb + + shawn.webb@hardenedbsd.org + + + + + Oliver + Pinter + + oliver.pinter@hardenedbsd.org + + + + + + Introducing HardenedBSD's New Binary Updater + secadm Beta Published + New Package Building Server + secadm + HardenedBSD Haswell Support + Nightly Builds for HardenedBSD Haswell Support + + + +

HardenedBSD has been hard at work improving the + performance and stability of our security enhancements. Security + flags are now per-thread instead of per-process, removing some + locking overhead. ASLR for mmap(MAP_32BIT) requests has been + refactored, but lib32 is now disabled by default.

+ +

We've developed a new binary update utility, + hbsd-update akin to freebsd-update. + In addition to normal OS installs, it can also update + jails and ZFS Boot Environments (ZFS BEs). Updates are + signed using X.509 certificates.

+ +

secadm 0.3-beta has landed. It has been + rewritten from scratch in order to be more efficient. As part of + the rewrite, the rule syntax has changed and users must update + their rulesets as described in the README.

+ +

Thanks to generous donations of a server from G2, Inc and + hosting from Automated Tendencies, we can now do full + package builds in just 35 hours, down from 75 hours. + This machine will also provide weekly binary updates for + the kernel and base system.

+ +

Owing partly to the needs of the developers, we have + an experimental branch that includes the work + &a.dumbbell; has underway for Haswell graphics support, + on top of &os; 11-current. Binary updates are also + provided for this branch.

+ +

Unfortunately, in order to focus our efforts on improving + HardenedBSD, we have had to pull back from submitting our ASLR + patches to &os;. The past two years' efforts to address comments + on the submission have taken their toll, and the effort is no + longer sustainable. We are proud to be based on &os; and believe + that the whole community could benefit from the security + technologies we are developing. We hope that someone else will + be able to step forward and finish off the task of integrating + ASLR into &os;.

+ + + + Automated Tendencies + + + + G2, Inc + + + + SoldierX + +