Re: selinux eradicator?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Mike McCarty wrote:
Rahul Sundaram wrote:
Mike McCarty wrote:


No, that was not my argument. My argument is that people are
commenting from a position of conjecture. There is no scientific
conclusive study showing that SELinux unarguably improves
security of machines.


There is. SELinux is MAC security framework and is based on scientific studies over decades which clearly show their advantages. Again read some of the work at NSA SElinux site.

Mandatory Access Control is not a thing, it is a technique. SELinux
is a thing, which may or may not be a good implementation of MAC.

There is lots of good evidence that SELinux is a good implementation. An example of this is LSPP and RBAC certification of RHEL 5 based on SELinux technology. You have zero practical experience with it.

I have already demonstrated that I have looked, I just disagree
with you.

You haven't demonstrated that you looked at any of the research since you made obviously incorrect speculations about it in your earlier mails.

It is faith that SELinux will survive at all.

This is too broad a statement and speculative to be meaningful.

Erm, ADDING SELinux was an intrusive effort, which is now difficult
to undo.

Nobody claimed it was easy to introduce a fundamental new security paradigm. You just prove my point that the effort to not install SELinux libraries offers pretty much no advantage over merely enabling or disabling it as required.

Rahul

--
fedora-list mailing list
fedora-list@xxxxxxxxxx
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
[Index of Archives]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora Magazine]     [Fedora News]     [Fedora Summer Coding]     [Fedora Laptop]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [SSH]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Gnome Users]     [KDE Users]     [Fedora Art]     [Fedora Docs]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Libvirt Users]     [Fedora ARM]

  Powered by Linux