Sankarshan (সঙ্কর্ষণ) wrote:
Jon Masters wrote:
Ok then let me just say it. I think the default should be permissive or
disabled by default. I was hoping to not have to say that - but I think
it's a lot safer on the mass userbase of Fedora than thrusting a fully
enforcing SELinux policy set upon them. If I'm having to hack on the
policy files on my laptop, there's no hope for a desktop user.
One can argue that the path to an objective where everything just
works with SELinux 'on' begins by forcing the bitter syrup down the
throats.
To extend your reasoning, if it were disabled by default, how would
one move towards just works ?
Agreed.
To put it more directly, why am I reading about your issues on
fedora-devel and not in bugzilla?
--CJD
--
fedora-devel-list mailing list
fedora-devel-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-devel-list