|
Security Enhanced Linux
What's New
Frequently Asked Questions
Background
Documents
License
Download
Participating
Mail List
Archives
Remaining Work
Contributors
Related Work
Press Releases
Information Assurance Research
NIARL In-house Research Areas
Mathematical Sciences Program
Sabbaticals
Computer & Information Sciences Research
Technology Transfer
Advanced Computing
Advanced Mathematics
Communications & Networking
Information Processing
Microelectronics
Other Technologies
Technology Fact Sheets
Publications
Related Links
|
SELinux Mailing ListRe: Debian SE Linux ?
From: Stephen Smalley <sds_at_tislabs.com>
Date: Wed, 19 Dec 2001 13:34:21 -0500 (EST)
> looking back on the list, I saw some people have discussed using Debian Russell Coker has a Debian kernel-patch package for SELinux at http://www.coker.com.au/selinux. I don't know whether the Debian folks have made any progress with the daemon and utility patches or the example policy configuration. I'm not sure what you mean when you say "I am still sorting out ext3 + initrd." The current release of SELinux works fine with ext3 - we were just waiting for ext3 to be merged into the mainstream kernel, and it is present in the 2.4.16 kernel. As far as initrd is concerned, you can probably make it work if you really need it. I think you just need to create an initrd image that includes a copy of the compiled policy configuration so that it is available.
> Looking at the way SELinux works, I assume I will have at least to alter You will need to adapt the daemon and utility patches to the corresponding Debian packages, although only a few of these patches are critical (login, sshd, crond). You will have to customize setfiles/file_contexts for your filesystem layout. If you build with NSA SELinux Development Module option, then you can run your system in permissive mode for a while to collect audit messages, and can then work on customizing the policy configuration based on those audit messages, possibly using Justin Smith's perl script. -- Stephen D. Smalley, NAI Labs ssmalley@nai.com -- You have received this message because you are subscribed to the selinux list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.Received on Wed 19 Dec 2001 - 13:47:23 EST |
|
|
Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009 |











