Skip to main content

KernelCare free patch > Unknown kernel

Comments

7 comments

  • sparek-3
    Kernelcare won't work on an OpenVZ VPS - which is what you appear to be using. The free symlink protection from Kernelcare will also not work. With OpenVZ the kernel space is shared from the host node. Consequently, your node appears to be using a very old kernel. Perhaps your OpenVZ provider (who you are paying for your VPS service) is using Kernelcare on the hostnode, so the old kernel version would not be alarming. But as far as symlink protection, you're out of luck with an OpenVZ VPS.
    0
  • carolainn
    Kernelcare won't work on an OpenVZ VPS - which is what you appear to be using. The free symlink protection from Kernelcare will also not work. With OpenVZ the kernel space is shared from the host node. Consequently, your node appears to be using a very old kernel. Perhaps your OpenVZ provider (who you are paying for your VPS service) is using Kernelcare on the hostnode, so the old kernel version would not be alarming. But as far as symlink protection, you're out of luck with an OpenVZ VPS.

    So...what would be the suggestion?
    0
  • carolainn
    In the Security Advisor I have this message too: Apache vhosts are not segmented or chroot()ed.Enable "Jail Apache" in the "Tweak Settings" area, and change users to jailshell in the "Manage Shell Access" area. Consider a more robust solution by using "CageFS on CloudLinux" I go to Tweak Settings and I have all my clients accounts configured with Disabled Shell, I only have the main account (mine) with Normal Shell. Would this configuration help with the symlink issue?
    0
  • cPanelMichael
    Apache vhosts are not segmented or chroot()ed.Enable "Jail Apache" in the "Tweak Settings" area, and change users to jailshell in the "Manage Shell Access" area. Consider a more robust solution by using "CageFS on CloudLinux" I go to Tweak Settings and I have all my clients accounts configured with Disabled Shell, I only have the main account (mine) with Normal Shell. Would this configuration help with the symlink issue?

    No, you'd need to use Mod_Ruid2 with the "EXPERIMENTAL: Jail Apache Virtual Hosts using mod_ruid2 and cPanel" jailshell" option enabled in "WHM >> Tweak Settings". You can enable Ruid2 via "WHM >> EasyApache 4" after determining which PHP handler to use with it based on the information documented at: PHP Handlers - EasyApache 4 - cPanel Documentation As far as symlink protection, since this is a Virtuozzo/OpenVPS server, you'd need to use the "Symlink race condition patch with EasyApache 4" option documented at: Symlink Race Condition Protection - EasyApache 4 - cPanel Documentation Thank you.
    0
  • carolainn
    Ok, I did that and still got the same warning and a new one: (x) Kernel does not support the prevention of symlink ownership attacks.You do not appear to have any symlink protection enabled through a properly patched kernel on this server, which provides additional protections beyond those solutions employed in userland. Please review Symlink Race Condition Protection. Thank you!
    0
  • cPanelMichael
    Hello, Those warnings are accurate and will still appear. While you do have some level of protection against symlink ownership attacks, it's not a kernel-level protection so that warning message appears. Thank you.
    0

Please sign in to leave a comment.