Re: SELinux - a call for end-of-life.



On Wednesday, September 01, 2010 14:31:55 Bruno Wolff III wrote:
On Wed, Sep 01, 2010 at 12:35:14 +0000,
JB <jb.1234abcd@xxxxxxxxx> wrote:
- it has to be simple to be acceptable and understandable by all sys
admins and

Selinux is fundamentally simple. When a process acts on an object, the
label of the process, the label of the object and the action are checked
in a table and either allowed or denied (with optional logging).

+1.

I could even go as far as to say that SELinux is simpler than iptables, both
from fundamental and practical point of view. And they basically serve the
similar purpose, one filters file access, the other filters network access.

It's just that some people are too lazy to read and understand two or three
man pages.

Best, :-)
Marko

--
users mailing list
users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe or change subscription options:
https://admin.fedoraproject.org/mailman/listinfo/users
Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines



Relevant Pages

  • Re: SELinux
    ... I've been a security wonk for many years, and the problem I have with ... SeLinux is that when it makes a decision I disagree with, ... To unsubscribe or change subscription options: ... Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines ...
    (Fedora)
  • Sound gone from yum upgrade from F17->F18
    ... SELinux: My SELinux claims it is disabled. ... Important Notice: This mailbox is ignored: e-mails are set to be ... To unsubscribe or change subscription options: ...
    (Fedora)
  • Re: Problems with K3b but not Brasero
    ... Have you tried running k3b after switching to SELinux permissive mode? ... Not every denial results in audit log messages. ... To unsubscribe or change subscription options: ...
    (Fedora)
  • Re: SELinux preventing login (Fedora 16)
    ... When you run in disabled mode, SELinux labels aren't written to the disk ... results in lots of denial errors. ... We just added the ability for samba to use ldap, ... To unsubscribe or change subscription options: ...
    (Fedora)
  • Re: Running httpd as a user
    ... as a regular user. ... I've poked at Google for a while but I don't see a way to tune SELinux ... Look through the output for a section refering to the relevant errors - ... To unsubscribe or change subscription options: ...
    (Fedora)