1 |
On Thu, 2004-04-29 at 17:18, Ed Wildgoose wrote: |
2 |
> Thanks for your endless patience! Rebuilding baselayout does indeed |
3 |
> seem to have allowed the policy to auto-load, and I can now log in via |
4 |
> console and ssh!! Wahoo |
5 |
|
6 |
Excellent! |
7 |
|
8 |
> I guess the next steps are to start playing with it. I'm a bit hesitant |
9 |
> about how to proceed though. There are clearly loads of access |
10 |
[cut] |
11 |
> lots of processes want urandom and cant have it |
12 |
|
13 |
This is a known issue with having ssp in glibc. |
14 |
|
15 |
> with mount not being able to access /etc/fstab I think? |
16 |
|
17 |
I'd need to see the denial. |
18 |
|
19 |
> What about things which look a little broken, eg emerging gpm and |
20 |
> selinux-gpm stops my policy compiling with something about ps_aux |
21 |
> (from memory) not being valid/defined. Is this a bug, or just |
22 |
> something I read the docs about and fix..? |
23 |
|
24 |
I need to update the gpm policy. |
25 |
|
26 |
> I can't help feeling that I haven't done the required reading to even |
27 |
> get started with selinux, but I'm not sure where to find the quickstart |
28 |
> guide? |
29 |
|
30 |
Well the quickstart guide here is for converting over to SELinux. I |
31 |
have a policy overview which covers a lot of the main SELinux concepts. |
32 |
|
33 |
http://www.gentoo.org/proj/en/hardened/selinux/selinux-policy.xml |
34 |
|
35 |
-- |
36 |
Chris PeBenito |
37 |
<pebenito@g.o> |
38 |
Developer, |
39 |
Hardened Gentoo Linux |
40 |
Embedded Gentoo Linux |
41 |
|
42 |
Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243 |
43 |
Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243 |