3 ms·
> The gist of the problems is that the policies are not transparent Yes. > (probably due to security reasons?) to the user/admin, did I get that right? No, t
by d2wa 4y ago
> The gist of the problems is that the policies are not transparent
Yes.
> (probably due to security reasons?) to the user/admin, did I get that right?
No, that isn’t the reason. They’re open source. The policies are, simply put, compiled binary blobs from a comprehensive set of allow-rules and label-path definitions. The complexity of analyzing and difficulty in overriding these complex rulesets is the problem. There are tools for interacting with the system, but good luck figuring out what they’re even called. All the tools are optimized for the ruleset developers and not the sysadmins that have to play by the rules (and are never told what the rules are).
Answering the question, “What do I need to label files that should be read by program X?” is waaay to hard. You’re expected to put your files in certain locations and then some things work out-of-the-box. However, there’s no documentation on where you’re supposed to put the files.
Sure, /var/www is where you put your website files by convention. Apache can read from that directory. But what if you put it in /var/web? You can relabel the directory, but it’s not at all apperent why everything grinds to a halt when you do. The /var/www dir is owned and readable by the apache user, but Apache still says complains it can’t read it. That’s the SELinux MAC in action blocking you from doing something totally normal just because you didn’t follow the strict rulesets (that no one told you about).
- prmoustache 4y ago> There are tools for interacting with the system, but good luck figuring out what they’re even called. They are mentionned in the selinux documentation of your distro. > Answering the question, “What do I need to label files that should be read by program X?” is waaay to hard. You’re expected to put your files in certain locations and then some things work out-of-the-box. However, there’s no documentation on where you’re supposed to put the files. The default directories are usually mentionned in the manuals of those programs. If you are using an selinux based distro, you know that if you don't use those default dirs you will have to label your custom dir. This is not hard to understand nor to do.