1 |
Hi everyone, |
2 |
|
3 |
I've been working on bringing the SELinux handbook as currently available on |
4 |
http://www.gentoo.org/proj/en/hardened/selinux/selinux-handbook.xml more |
5 |
up2date. It's somewhat of a rewrite, but with all elements of the original |
6 |
SELinux handbook still inside it (apart from the troubleshooting as I guess |
7 |
those are quite outdated, being from 2006 and older). |
8 |
|
9 |
The draft is currently available in the hardened-docs.git repository. In |
10 |
http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-docs.git;a=tree;f=html/selinux;hb=HEAD |
11 |
you should be able to select individual chapters (HTML format) in the "raw" |
12 |
tree to view them somewhat like they would on the Gentoo site, but for your |
13 |
convenience there's also a PDF available at |
14 |
http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-docs.git;a=tree;f=pdf;hb=HEAD |
15 |
|
16 |
The new draft is structed in three parts: |
17 |
|
18 |
Part A - Introduction to Gentoo/Hardened SELinux |
19 |
Chapter 1. Enhancing Linux Security |
20 |
Chapter 2. SELinux Concepts |
21 |
Chapter 3. The SELinux (Reference) Policy |
22 |
Part B - Using Gentoo/Hardened SELinux |
23 |
Chapter 1. Gentoo SELinux Installation / Conversion |
24 |
Chapter 2. SELinux Commands |
25 |
Chapter 3. Running in Permissive Mode |
26 |
Chapter 4. Switching to Enforcing Mode |
27 |
Chapter 5. Adding SELinux Policy Modules |
28 |
Part C - Appendices |
29 |
Chapter 1. Troubleshooting SELinux |
30 |
Chapter 2. SELinux Reference Material |
31 |
|
32 |
If time permits, part A will have a fourth chapter on virtualization and |
33 |
SELinux, but I gather that's more for the next update on the documentation. |
34 |
|
35 |
The document is currently written with the ebuilds in hardened-development |
36 |
overlay in mind, so everyone interested in giving Gentoo Hardened with |
37 |
SELinux a try can use the draft documentation with the |
38 |
"hardened-development" overlay. |
39 |
|
40 |
For the time being the document only supports the type enforcement features |
41 |
of SELinux. MLS/MCS has not been touched yet. |
42 |
|
43 |
Feedback is always welcome, including language mistakes, typos or just plain |
44 |
lies. |
45 |
|
46 |
Wkr, |
47 |
Sven Vermeulen |