Re: How best get rid of SELinux?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 9/21/07, Timothy Murphy <tim@xxxxxxxxxxxxxxxxxxxxxx> wrote:
> Arthur Pemberton wrote:
>
> > Selinux is another layer of security, it isn't a replacement of any
> > security layers, I see no reason why anyone feels such apparently
> > hostility to this piece of technology.
>
> While I'm not hostile to SELinux,
> I'm also not convinced it actually gives any protection in the real world.
> I've never seen anyone say, "Thank God I was running SELinux,
> or I would have been in a mess".

So... would you like me to tell a story of why I like SELinux? And how
it saved me from my own weak sysadmin practices?

> I see at once from my logwatch that thousands of lunatics
> are hurling silly packets at my machine,
> and I'm grateful to shorewall for keeping them out.

Please. Lets keep firewalls out of the topic, they SELinux i
complementary to firewalls.

> I suspect that at the moment SELinux is more of an advertising ploy,
> "Windows cannot be secured, but Linux can",
> than a useful defence against any real danger.

Your suspicions, while reasonable are untrue.

> There probably will be a real danger in the future, if Linux thrives.
> So it is certainly a good idea to build up defences now.

The earlier we start, the better.

> Personally, I run SELinux in permissive mode,
> intending to see what it turns up - one day, when I have time ...

I either run it (in targeted mode) or I don't - I do on servers, don't
on desktops/laptops

-- 
Fedora 7 : sipping some of that moonshine
( www.pembo13.com )

-- 
fedora-list mailing list
fedora-list@xxxxxxxxxx
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
[Index of Archives]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora Magazine]     [Fedora News]     [Fedora Summer Coding]     [Fedora Laptop]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [SSH]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Gnome Users]     [KDE Users]     [Fedora Art]     [Fedora Docs]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Libvirt Users]     [Fedora ARM]

  Powered by Linux