LWN.net Logo

Just an SELinux DTE Policy

Just an SELinux DTE Policy

Posted Dec 5, 2004 3:25 UTC (Sun) by AnswerGuy (subscriber, #1256)
In reply to: Book review: SELinux by Method
Parent article: Book review: SELinux

I believe that comment was referring specifically to an SELinux DTE (domain type enforcement) policy and not to an enterprise policy for an entire organization.

My problem with SELinux in general is the complexity of these policies. They might provide a workable solution for organizations that can devote whole teams of qualified developers and other personnel to developing, testing, and maintaining these policy files. However, they are not practical for the lone sysadmins at smaller organizations, nor even for small systems administration teams and most mid-sized installations and that serve the departments of some of the larger decentralized enterprises.

I still say that systrace offers the right balance of features and simplicity for most of us, and provides features that I haven't seen from any of the many other security enhancement patches and packages for Linux.

Jim Dennis


(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.