LWN.net Logo

SELinux and Fedora

SELinux and Fedora

Posted Jul 11, 2008 14:52 UTC (Fri) by yyidth (guest, #18842)
Parent article: SELinux and Fedora

Honestly, please stop writing articles like this. Why is LWN acting as an apologist for a
failed security infrastructure? The kernel team has all but kicked them out with the opening
of the LSM api and inclusion of SMACK in the source tree. In 5 years those of us who are
professional Unix admins will look back at SELinux with annoyance and be glad it's gone. One
or another of the current crop of tools with equivalent functionality, a usable configuration
methodology and complete documentation will have replaced it across the board.

I have a great deal of respect for both the work and to workers that is SELinux. It was
basically the first, but as is often the case with a first attempt at a new tech the
implementation falls off the mark. In the case of SELinux a mistake was made in moving to far
away form standard Unix behavior and a config system that seems to try its best to be obtuse.
On top of the complete lack of documentation and the complete uselessness of the log messages
SELinux ends of being unusable by a busy professional admin.

And so, until Fedora, Redhat, Ubuntu and the like move forward problems with SELinux are best
dealt with using the directive SELINUX=disabled in /etc/selinux/config.


(Log in to post comments)

SELinux and Fedora

Posted Jul 11, 2008 18:55 UTC (Fri) by nix (subscriber, #2304) [Link]

I'm not much of an SELinux fan, but your claim that 'the kernel team has 
all but kicked [the SELinux developers? SELinux itself?] out with the 
opening of the LSM api' is ludicrous. Providing extra choices doesn't mean 
that the existing choices are anathematized!

SELinux and Fedora

Posted Jul 11, 2008 20:36 UTC (Fri) by luya (subscriber, #50741) [Link]

To be analogical, it looks like someon is turning off ABS and traction control.

SELinux and Fedora

Posted Jul 11, 2008 21:34 UTC (Fri) by Los__D (guest, #15263) [Link]

Honestly, please STFU, and stop telling LWN what to cover.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds