4 ms·
I ran a centos server for a while (ran= not my responsibility any longer) with SE Linux and a tomcat portal app, as well as other, custom web apps (ruby on rail
by cessor 10y ago
I ran a centos server for a while (ran= not my responsibility any longer) with SE Linux and a tomcat portal app, as well as other, custom web apps (ruby on rails with a mail queue and mysql backend, etc). I always left it in permissive, because I couldn't figure out how to properly configure it.
I tried understanding the principles behind it and configuring the different exceptions for several classes, but often, this didn't work (e.g. I had used wrong class, or enabled exceptions that were still blocked). The users of the rails app kept calling, asking me why this or that feature wouldn't work. It was impossible for me to configure all exceptions - to me this was not surprising, given the complexity of the software that we had installed. I simply deemed the apps too complex and too "feature rich" to configure all SELinux exceptions manually.
I then understood that there is a different way: To set it to permissive, keep it running for a while and then generate an installable permissions profile, allowing all occured violations as some kind of permissable exceptions.
This made sense to me, however it required downloading some dubious python script, that would create some dubious binary file. I got this to work, but then again, this or that feature was blocked. I finally kept it running on permissive. This is my individual story. The article makes it look as if it was really simple to configure it (When I started with SE I tried similar moves but never got it to work).
So, is it just me, or might it be that SELinux just has a major usability issue?
- snuxoll 10y agoWhy aren't you testing things with SELinux before you deploy them to production? Also, if you constantly need to alter your policy it sounds more like your application is poorly-behaved, not that SELinux is your problem. audit2allow is a great tool for simplifying the development of SELinux policies, but it doesn't remove some hand-crafted modifications to policies, especially in regards to file contexts (fcontext).
- justanotherbody 10y agoKeep in mind there are a LOT of apps deployed on systems with SELinux with few, if any, tests Further, the divide between ops and developers in many cases leaves this as an unsolvable problem - it's not the dev's job to do sysadmin, and ops lacks the expertise (or time) to comprehensively analyze the code base You're right that this makes the app poorly behaved, but if that can't be addressed then... permissive mode it is
- snuxoll 10y agoEveryone keeps telling sysadmins they need to be able to write code, how about developers start learning more about how their applications are deployed. I wear both hats, and then some more on top of that - if someone on my team is doing something that will make deployment and security difficult I make sure to nip it in the bud during testing.