Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Feedback on updated SELinux docs
Date: Mon, 26 May 2014 07:02:15
Message-Id: 20140526070210.GA3481@gentoo.org
In Reply to: [gentoo-hardened] Feedback on updated SELinux docs by "S. Lockwood-Childs"
1 On Sun, May 25, 2014 at 01:13:58AM -0700, S. Lockwood-Childs wrote:
2 > Overall, it looks really good. Kudos for a job well done.
3 >
4 > I put in a couple of edits to try to improve a couple parts that seemed
5 > a little hard to follow, but the main area for improvement I see is that
6 > policy types are not discussed as a core concept. "Users and logins" mentions
7 > targeted policy in the context of unconfined_u, but there's no preceding
8 > section that could be linked in as a reference for more information.
9 > The "expert" section on policy store does mention the standard policy types,
10 > but it seems important enough topic that it deserves a mention in the
11 > intro article (in particular, enough to guide user on choice between strict
12 > and targeted).
13
14 Hi
15
16 Thanks for the feedback and the edits.
17
18 I was hoping that policy stores were sufficiently documented in the
19 installation instructions [1] as most users will not need to switch types
20 afterwards.
21
22 [1]
23 https://wiki.gentoo.org/wiki/SELinux/Installation#Choosing_a_SELinux_policy_type
24
25 I am considering moving the policy document [2] to the user guides though. I
26 could enhance that document with more information about policy stores as
27 well without touching on the more in-depth feedback that is in the policy
28 store document [3]
29
30 [2] https://wiki.gentoo.org/wiki/SELinux/Policy
31 [3] https://wiki.gentoo.org/wiki/SELinux/Policy_store
32
33 Wkr,
34 Sven Vermeulen

Replies

Subject Author
Re: [gentoo-hardened] Feedback on updated SELinux docs "S. Lockwood-Childs" <sjl@××××××××××××.com>