3 ms·
Leaving selinux on would be more easy if the access denials were put in the primary system log and/or in dmesg and did not just go in the audit log. It takes to
by sn 10y ago
Leaving selinux on would be more easy if the access denials were put in the primary system log and/or in dmesg and did not just go in the audit log. It takes too long to figure out what the problem is with selinux. That being said we leave it on in production, since with ansible we find the problem once and then incorporate the changes into our playbooks.
I've used both apparmor and selinux and while it was pretty easy to figure out how to write a custom profile for apparmor, it's not easy to do the same for selinux. If a custom profile for selinux could be made as easy to write, that would help a lot.
- cmurf 10y agoAt least on Fedora, for a few releases now, the audit messages appear in the journal, which is the primary system log.