Changes
added link to TPE description
== TPE (Trusted Path Execution) ==
Starting from 2.6.18-028stab047.1 stable kernels OpenVZ kernels support TPE [http://en.wikibooks.org/wiki/Grsecurity/Appendix/Grsecurity_and_PaX_Configuration_Options#Trusted_Path_Execution_.28TPE.29] grsecurity feature out of the box.
Which means root user can configure TPE inside VE as usual, i.e. via the following /proc files:
* /proc/sys/kernel/grsecurity/grsec_lock