1 |
On Sun, 2007-06-24 at 20:41 -0400, Bill Sharer wrote: |
2 |
> Chris P and company |
3 |
> |
4 |
> While rummaging through my dmesg's I found a lot of denials related to |
5 |
> the urandom device and then found the global_ssp boolean when looking at |
6 |
> stuff through apol. (20070329 ref policy btw). Anyway I also saw this |
7 |
> |
8 |
> http://www.nsa.gov/selinux/list-archive/0603/thread_body35.cfm |
9 |
> |
10 |
> documenting this gentoo-only flag. The only trouble is that the |
11 |
> booleans.conf that unpacks with the reference policy has this set to |
12 |
> false. Is this worth a trip to bugzilla to write it up? |
13 |
|
14 |
setsebool -P global_ssp 1 |
15 |
|
16 |
That will enable it and make it so it is set on boot. The purpose of |
17 |
booleans is to provide options to the users. |
18 |
|
19 |
-- |
20 |
Chris PeBenito |
21 |
<pebenito@g.o> |
22 |
Developer, |
23 |
Hardened Gentoo Linux |
24 |
|
25 |
Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243 |
26 |
Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243 |