3 ms·
I do know this, I'm currently putting together a training course on authoring SELinux policy. Surely the fact that 'disabling SELinux' is the top result on the
by iou 5y ago
I do know this, I'm currently putting together a training course on authoring SELinux policy.
Surely the fact that 'disabling SELinux' is the top result on the subject in Google or StackOverflow will tell you that you would be in the minority of developers that like working with it and find it easy to do so.
I think there's more to it than just simply running an app without receiving an AVC complaint in auditd, you need to be able to test that the controls you put in place actually protect the application in some way, this does not come for free with audit2allow and other such generative tools.
- cpncrunch 5y agoThe problem I found (on Centos 8) is that audit sometimes denies but nothing is logged. I found this is the case when an apache script tries to kill another process. It required 2 separate policies: one of which audit2allow came up with, and another I had to figure out myself after a whole bunch of time scouring stackoverflow. After that I just gave up on selinux and turned it off, as I just couldn't trust it. If it actually did what it was supposed to do in a reasonable manner, people would use it.
- recentdarkness 5y ago> The problem I found (on Centos 8) is that audit sometimes denies but nothing is logged I doubt that. journalctl has always given me something when there was an actual denial. You might just not have looked right
- cpncrunch 5y agoI did. It is trivial to recreate.