LWN.net Logo

SELinux and PostgreSQL: a worthwhile union?

SELinux and PostgreSQL: a worthwhile union?

Posted Dec 11, 2009 0:32 UTC (Fri) by Cyberax (✭ supporter ✭, #52523)
In reply to: SELinux and PostgreSQL: a worthwhile union? by marcH
Parent article: SELinux and PostgreSQL: a worthwhile union?

SELinux policies are horrible.

So most 'casual users' and administrators just turn SELinux off. Besides, with SELinux you also need to 'label' your filesystem. And if you're using an NFS, SMB or FAT32 partition - tough luck, then.

That's why I'm advocating for AppArmor - it's quite easy to use. You can write a policy for a simple daemon in 10 minutes, literally. And it'll be intuitively understandable. And it won't require you to label you filesystem.

And it'll be just as secure for most applications as is SELinux.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds