Nuxified

FOSS technologies explained

  • Useful Articles
  • Blogs
  • Images
  • Tips
  • Archives

November 13, 2007

SELinux nightmare

Well, it’s actually not a real nightmare, I just thought this would be a cool title.

As some of you might know I really favor SELinux over AppArmor, although it’s quite hard to use.
Now that EasyLFS is mostly done I am working on it’s SELinux-policy, which is based on the Reference Policy by Tresys.

So far work is progressing quite nicely, the only thing I don’t like about it is that I more or less have no real clue what I’m doing there. Okay, I understand that programs need to access inodes in a certain way, like getting attributes, reading, writing, etc. But what’s still far beyong my understanding is all that domain-crap with it’s transitions and what-nots.
Luckily it seems that currently I don’t really need to care for that too much because I am just building a targeted policy, but still I’d to be able to some day also offer a strict policy for SELinux. That would be so cool!

So, what I am going to do now is this: First I will study the documentation of the Reference Policy on the Tresys-site. If that’s not enough I’m going to buy a fat kickass book about SELinux, probably “SELinux by Example” and read that, instead of continuing my journey to the Dark Tower (I have been there already anyway, just reading it again because I got nothing else right now 😉 ).

I really want to really understand all that stuff. Not only in order to be able to modify the policy. Modifying simple policies is actually easy enough when you check the logs and maybe use audit2allow to tell what’s up. And also SLIDE, that cool SELinux-Policy-development-plugin for Eclipse is quite helpful, but being able to write my own modules to add to the Reference Policy would be a really nice thing.

Well, let’s see. But it’s really time to dive deeper into this.

Newsflash wrote:

On other news it was announced that EasyLFS is progressing nicely. It’s developer stated that there are only few problems left and that most of the current work is going into the SELinux-policy. Also he said that he is confident that EasyLFS 0.4 will be released this year.

US-President Bush and german chancellor Merkel declared that a public holiday will be introduced to celebrate the release of the coolest and hottest version of EasyLFS the world has seen so far.

Share this:

  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)

Related

Article by reptiler / Community Blogs

Learn Unix

I run Unix Tutorial website and help anyone interested to pick up Unix skills. If you have questions or just want to share your ideas – please join the Unix Tutorial on Facebook.

Tech Stack Solutions

Tech Stack Solutions is my company that provides Unix support. Sign up or simply get in touch to find out how I can help!

Search this Website

You May Also Like

Recent Posts

  • Advice on using SUDO
  • FFmpeg 4.0
  • KDE Plasma 5.9.0 Release
  • How to Install Ubuntu Linux without a DVD or USB
  • How to Securely Save All Your Passwords with Keepass
  • 9 Signs You Should Use Linux on Your Computer
  • The Easiest Way to Optimize Your MySQL Database Performance
  • Setting up a Linux Web Development Environment in Windows
  • Hunting Down Disk Space Hogs on Linux Command Line
  • 6 Simple Android Apps for Monitoring and Managing Your Linux Server

Archives

Categories

  • Community Blogs
  • Images and Screenshots
  • News
  • Technical Topics
  • Useful Articles

Basic Unix Commands

Basic Unix Commands
  • ls command
  • mkdir command
  • man command in unix
  • cd command - change directory
  • uname command

Advanced Unix Commands

Advanced Unix Commands
  • ln command - symlinks
  • tune2fs unix command - filesystem parameters
  • du command - disk usage
  • lsb_release command
  • find unix command

Unix Reference

Unix Reference
  • SSH port forwarding
  • unix commands
  • visudo tutorial
  • mtime unix
  • lrwxrwxrwx
  • Unix Tutorial digest

Unix Books

Unix Tutorials

Unix How-Tos
  • check raspbian version
  • autostart in KVM
  • List files in Ubuntu package
  • check CentOS version
  • create bootable USB in MacOS
  • Useful Articles
  • Blogs
  • Images
  • Tips
  • Archives

Copyright © 2023 · Education Pro Theme on Genesis Framework · WordPress · Log in