LWN.net Logo

Number 9, number 9. Fedora 9 Preview has been cleared for takeoff!

Number 9, number 9. Fedora 9 Preview has been cleared for takeoff!

Posted Apr 19, 2008 20:40 UTC (Sat) by michich (subscriber, #17902)
In reply to: Number 9, number 9. Fedora 9 Preview has been cleared for takeoff! by dany
Parent article: Number 9, number 9. Fedora 9 Preview has been cleared for takeoff!

That article was about how a security expert would implement a custom security policy. It was
not about everyday life on a SELinux enabled system. :-)


(Log in to post comments)

Number 9, number 9. Fedora 9 Preview has been cleared for takeoff!

Posted Apr 19, 2008 22:48 UTC (Sat) by nix (subscriber, #2304) [Link]

Serge started the article with a quote talking about simplifying 
administration. I finished it wondering how hellish complex the 
administration could have been beforehand if *that* made it simpler...

Number 9, number 9. Fedora 9 Preview has been cleared for takeoff!

Posted Apr 20, 2008 0:36 UTC (Sun) by michich (subscriber, #17902) [Link]

Serge probably had a different meaning of "administration" in mind than 
you. He meant the kind of administration where you actively take 
advantage of SELinux and confine your custom applications by writing MAC 
policies for them. You do this by adding SELinux types, roles and rules. 
If you find it too difficult, then don't do it. You can simply run your 
application unconfined, while leaving at least all the usual daemons in 
their confined domains.

But writing completely new SELinux policies is not what the vast majority 
of administrators have a need to do (but if they do, they can start with 
the SELinux Policy Generation GUI tool).

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds