Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Posted Feb 27, 2020 19:33 UTC (Thu) by Cyberax (✭ supporter ✭, #52523)In reply to: Impedance matching for BPF and LSM by rahulsundaram
Parent article: Impedance matching for BPF and LSM
Posted Feb 27, 2020 19:50 UTC (Thu)
by pizza (subscriber, #46)
[Link] (3 responses)
(If anything, "general purpose UNIX-like Linux" is the actual niche use case these days..)
Posted Feb 27, 2020 19:53 UTC (Thu)
by Cyberax (✭ supporter ✭, #52523)
[Link] (2 responses)
It's no wonder that SELinux can work within these environments.
SELinux still fails within environments that require flexibility or extensibility.
Posted Feb 29, 2020 12:31 UTC (Sat)
by cpitrat (subscriber, #116459)
[Link]
Posted Feb 29, 2020 20:45 UTC (Sat)
by zlynx (guest, #2285)
[Link]
Only with administrators who can't be bothered to learn how it works.
This reminds me of PHP web developers who can't be bothered to learn Unix file permissions and mark everything chmod 777.
Posted Feb 27, 2020 20:13 UTC (Thu)
by SEJeff (guest, #51588)
[Link] (6 responses)
Posted Feb 27, 2020 20:18 UTC (Thu)
by Cyberax (✭ supporter ✭, #52523)
[Link] (5 responses)
Many RedHat forks (Amazon Linux, Scientific Linux) also pretty much ignore SELinux and barely test it.
Posted Feb 27, 2020 20:39 UTC (Thu)
by mohg (guest, #114025)
[Link] (1 responses)
As a binary rebuild of RHEL, Scientifix Linux supports whatever the equivalent RHEL does.
Posted Feb 27, 2020 20:46 UTC (Thu)
by Cyberax (✭ supporter ✭, #52523)
[Link]
However, plenty of software doesn't support it. Like SUN (RIP) Grid Engine forks, or good old Hadoop.
Posted Feb 27, 2020 20:59 UTC (Thu)
by rahulsundaram (subscriber, #21946)
[Link]
I have worked in multiple large enterprises which had SELinux in enforcing mode. I am not sure what this argument is about
Posted Feb 29, 2020 2:14 UTC (Sat)
by Rudd-O (guest, #61155)
[Link]
Perhaps the "niche" is only on your mind, brah.
Posted Mar 3, 2020 17:45 UTC (Tue)
by frostsnow (subscriber, #114957)
[Link]
Impedance matching for BPF and LSM
("niche" does not mean "
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
I have no idea in what sense it could be said to "pretty much ignore SELinux".
Impedance matching for BPF and LSM
> I have no idea in what sense it could be said to "pretty much ignore SELinux".
The problem is that SL doesn't do anything with SELinux. If you use it as a RHEL rebuild it works just as RHEL.
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
Impedance matching for BPF and LSM
