CAP_SYS_ADMIN: the new root
CAP_SYS_ADMIN: the new root
Posted Mar 16, 2012 9:11 UTC (Fri) by mjthayer (guest, #39183)In reply to: CAP_SYS_ADMIN: the new root by mjthayer
Parent article: CAP_SYS_ADMIN: the new root
To continue off-track and start on the old song - I think that one of the things that irks me most about SELinux is that I have so much trouble nailing down what it is and does, which I think is down to the fact that it doesn't try to solve a precise problem but more to be a general solution to all security issues. As an example, it covers both forbidding people to change the permissions on sensitive files they own, but also forbids binaries from modifying their own executable code without express permission (actually, to add to the confusion, I think there is an official workaround for that involving having two mappings for the memory, one writeable and one executable). Both laudable goals, but perhaps they should be a bit more clearly separated.
