1 |
On Tue, 2007-07-31 at 13:32 +1200, John Huttley wrote: |
2 |
> Wandering through the man pages, i've found load_policy and checkpolicy |
3 |
> |
4 |
> Have they been obsoleted by semodule ? |
5 |
|
6 |
No, checkpolicy is still used if one wants to built a monolithic policy. |
7 |
High assurance systems (like government systems, for example) generally |
8 |
have static policy since the system doesn't change; thus, building a |
9 |
monolithic policy makes sense still. Most other people have more |
10 |
dynamic systems that change as you add/remove/upgrade packages and make |
11 |
more sense being modular. |
12 |
|
13 |
Load_policy is called by semodule, to load the policy into the kernel. |
14 |
|
15 |
-- |
16 |
Chris PeBenito |
17 |
<pebenito@g.o> |
18 |
Developer, |
19 |
Hardened Gentoo Linux |
20 |
|
21 |
Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243 |
22 |
Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243 |