On Thu, 2004-10-07 at 19:11 +0200, Arjan van de Ven wrote: > On Thu, 2004-10-07 at 19:00, Stephen Smalley wrote: > > Or alternatively, customize the policy to fit your needs. That is why > > SELinux is flexible - because no single policy meets everyone's needs. > > while that is true it sure should be possible to have a policy that can > be used by default and doesn't change existing "this works" practice. > Even if that policy allows a bit more than you would want. > If such a policy can me made I would be happy. In the beginning I thought SELinux sounded good, but experience with it suggests that writing policy to such a fine-grained is just too labor intensive and problematic.