ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Proposed Session: SELinux Deep Dive

    IT Discussion
    linux selinux mangocon
    6
    11
    2.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stacksofplatesS
      stacksofplates
      last edited by

      I figured this might be a good topic to get deeper into than just chcon -t and chcon --reference.

      1 Reply Last reply Reply Quote 4
      • DashrenderD
        Dashrender
        last edited by

        Agreed. I'm not even sure what it's purpose is.

        stacksofplatesS 1 Reply Last reply Reply Quote 0
        • W
          WingCreative
          last edited by

          While we wait for MangoCon: I found this video helpful for understanding what it does and how to deal with it without disabling it altogether.

          1 Reply Last reply Reply Quote 1
          • stacksofplatesS
            stacksofplates
            last edited by

            There's a good one called SELinux for mere mortals. It's a good overview.

            1 Reply Last reply Reply Quote 0
            • stacksofplatesS
              stacksofplates @Dashrender
              last edited by stacksofplates

              @Dashrender said:

              Agreed. I'm not even sure what it's purpose is.

              It adds another layer of security over DAC called MAC (Mandatory Access Control) which allows you to assign classification labels and contexts to files, folders, services, and even ports.

              For example say you have a web server and apache becomes compromised. The only thing Apache can touch are things with specific httpd labels.

              1 Reply Last reply Reply Quote 2
              • stacksofplatesS
                stacksofplates
                last edited by stacksofplates

                http://people.redhat.com/tcameron/summit2010/selinux/SELinuxMereMortals.pdf

                MattSpellerM 1 Reply Last reply Reply Quote 3
                • MattSpellerM
                  MattSpeller @stacksofplates
                  last edited by

                  @johnhooks upvotes for ninja spaghetti link fix

                  1 Reply Last reply Reply Quote 1
                  • stacksofplatesS
                    stacksofplates
                    last edited by

                    Here's another. I can't find original link since I'm on my phone and lazy, so I'll share the link from my box account.

                    https://app.box.com/s/tu3z6nf7zscp8oheoqwn539atu288zws

                    1 Reply Last reply Reply Quote 1
                    • scottalanmillerS
                      scottalanmiller
                      last edited by

                      Now the next question: who would we get to teach it?

                      1 Reply Last reply Reply Quote 1
                      • NerdyDadN
                        NerdyDad
                        last edited by

                        I'm resurrecting this topic for suggestion to discussion for the DFW Mango Meetup.

                        scottalanmillerS 1 Reply Last reply Reply Quote 1
                        • scottalanmillerS
                          scottalanmiller @NerdyDad
                          last edited by

                          @NerdyDad said in Proposed Session: SELinux Deep Dive:

                          I'm resurrecting this topic for suggestion to discussion for the DFW Mango Meetup.

                          Oh nice.

                          1 Reply Last reply Reply Quote 1
                          • 1 / 1
                          • First post
                            Last post