1 |
Hi, |
2 |
|
3 |
I'm searching for a security solution. Since I like the |
4 |
UNIX-permissions, selinux ist not my favorite. I also would like to |
5 |
activate those additional rules for several processes only. I don't |
6 |
want to have them systemwide. It's for keeping an eye on those |
7 |
programms which are reachable from the internet. |
8 |
|
9 |
>From my investigations, systrace or AppArmor would fit. Both are not |
10 |
available for Gentoo AFAIK. Is it possible to do this with |
11 |
- Grsecurity/RBAC? |
12 |
- RSBAC? |
13 |
- Selinux? |
14 |
To be precise, the default rule shall be: Allow everything. |
15 |
I simply want to keep programs like qmail-ldap, dovecot and so on |
16 |
within their allowed limits. |
17 |
|
18 |
Regards, |
19 |
Aiko |
20 |
-- |
21 |
:wq |
22 |
-- |
23 |
gentoo-hardened@g.o mailing list |