top | item 13548690

(no title)

hadfgdasf | 9 years ago

I will continue to disable SELinux, and no number of arcane articles about how EASY it is will convince me otherwise.

Stick that in your pipe and smoke it.

discuss

order

saywatnow|9 years ago

Your loss. I agree that the way it's sold as "EASY" (caps appropriate) is a bit ridiculous, but SELinux does add a stong layer of protection from vulnerabilities in one service leading to total server pwnage. Ignore the rhetoric and try to work with it - the peace of mind pays off.

sgt|9 years ago

What if an app does something during runtime that you had not catered for? This effectively means potential downtime for the app while your admins are trying to figure out why the app is failing.

I agree SELinux adds something to the table, but the article shows two examples (httpd_sys_content_t and httpd_can_network_connect). Let's assume there is a third httpd_can_foo_bar that is required down the line. And then a http_can_bar_quux a few hours after that. All in all this can be a bit risky. Perhaps if there was an easier way to administer SELinux?

jlgaddis|9 years ago

It really isn't that difficult once you understand the terminology and methods. It is absolutely worth the effort to learn, in my opinion.