3 ms·
SELinux is so ridiculous. If you want a real security on linux where root is not God ! Go to this site. https://www.rsbac.org/ https://www.rsbac.org/ It's l
by Edynamic77 4y ago
SELinux is so ridiculous.
If you want a real security on linux where root is not God !
Go to this site.
https://www.rsbac.org/ https://www.rsbac.org/
It's little difficult to implement (by kernel customisation) but there is a learning mode to secure all Linux structure
Be "root" is not be "God" after implementation. You will must ask to Security Officer (SecOff)
You can speak of "Evaluation Assurance Level" with this security solution and push SELinux into a trash.
- dale_glass 4y agoroot is not God under SELinux either. root processes are also confined.
- themulticaster 4y agoIndeed, that's possible and a good idea - as long as you're not talking about user shells [1] running as confined processes. It turns out that having an unconfined root shell is actually not a bad idea unless you're interested in extreme levels of security. My experience is that confining user shells is a significant hassle. Running daemon processes etc. as confined root on the other hand is a good idea, but if you're going to the trouble of confining a root process you might as well just run it as a normal user instead if that's possible. [1] Meaning shells used by a real person attached to ssh.