3 ms·
I would love for SELinux to be easier, but as far as I can tell it's the only game in town. I would never put anything internet facing that wasn't SELinux. No
by jbjohns 15y ago
I would love for SELinux to be easier, but as far as I can tell it's the only game in town. I would never put anything internet facing that wasn't SELinux. Normal unix rights are simply not sufficient. Once you break into a program you can do everything the user that program is running under can do. Sure, you can create a new user for every bloody program/service you have but that means escalating privileges, etc.
With SELinux I no longer have to worry about any switching-user nonsense. I can just give that service those specific rights. In that sense it is a lot simpler than the overly simplistic approach we've been using.