3 ms·
Isn't SELinux turned on by default in most mainstream distros these days? I think it's not "nightmarishly difficult" as it is "nightmarishly difficult" to use
by jbjohns 5y ago
Isn't SELinux turned on by default in most mainstream distros these days? I think it's not "nightmarishly difficult" as it is "nightmarishly difficult" to use with the most complicated scenarios you can come up with but the system will let you be as permissive or restrictive as you like. I really wish more would be invested in making SELinux more convenient because it appears to me to be the best solution when dealing with virus', malware and so on.
- throwawayboise 5y agoIt is on by default in my experience, but also often disabled immediately after installation.
- doubled112 5y agoI've always considered SELinux a RHEL/Fedora thing. It's not very inconvenient these days, and those distros include tools that will write policies for you. Debian and Ubuntu distros use AppArmor. OpenSUSE MicroOS/Kubic also seem to have SELinux enabled by default, but I believe Leap and Tumbleweed use AppArmor by default. Other than that, I don't think it's hugely popular. Alpine, Arch, and Slackware have neither enabled by default. NixOS has a working group for SELinux but I'm not sure what state it's in.