3 ms·
From my relatively basic understanding of SELinux, it seems like has a lot of powerful mechanisms for enforcing security policy, but a lackluster interface for
by kritr 4y ago
From my relatively basic understanding of SELinux, it seems like has a lot of powerful mechanisms for enforcing security policy, but a lackluster interface for actually showing violations or creating robust policy.
Luckily, I think there’s a lot of community work coming up to make these policies easier to write and more robust.
For example: https://github.com/dburgener/cascade https://github.com/dburgener/cascade
Is a DSL for writing SELinux policy, and seems to aim to provide a better audit tool.