Gentoo Archives: gentoo-hardened

From: "Simpson
To: gentoo-hardened@l.g.o
Subject: RE: [gentoo-hardened] Xen and SElinux
Date: Wed, 20 Dec 2006 17:56:37
Message-Id: 7A75E851BF0EA743ABBC9D78A4BA4979EA233F@wgiptcemx03.wgint.net
1 > -----Original Message-----
2 > From: Fred Blaise [mailto:fred.blaise@×××××××.com]
3 > Sent: Wednesday, December 20, 2006 9:37 AM
4 > To: gentoo-hardened@l.g.o
5 > Subject: [gentoo-hardened] Xen and SElinux
6 >
7 > Hi all
8 >
9 > I would like to setup xen with SElinux. The packages version I have
10 are:
11 >
12 > app-emulation/xen
13 > Latest version available: 3.0.2
14 > Latest version installed: 3.0.2
15 >
16 > sys-kernel/xen-sources
17 > Latest version available: 2.6.16.28-r1
18 > Latest version installed: 2.6.16.28-r1
19 >
20 > However, I can't find any references to SELINUX in the .config file.
21 >
22 > I have googled around and ask on the xen-users mailing list about how
23 to
24 > include SElinux, and have been redirected here.
25 >
26 > I am seeking advices on how to do it.
27 >
28 > Thanks for the time and help.
29 >
30 > Best,
31 > fred
32 > --
33 > gentoo-hardened@g.o mailing list
34
35 SELinux is available in all 2.6 kernels. To use Gentoo with Xen and
36 SELinux, I had to switch to the SELinux 2006.1 profile, which is still
37 in testing. This is the first Gentoo with support for modular SELinux
38 reference policy, which has a policy module for Xen. The SELinux
39 upgrade, however, requires glibc 2.4 which is not yet available for
40 hardened gcc.
41
42 Info on migrating Gentoo to SELinux 2006.1, as well as modifying a
43 kernel for use with SELinux is available here:
44 http://archives.gentoo.org/gentoo-hardened/msg_06462.xml
45
46 Use the latest xen-sources kernel and configure it for SELinux. Note
47 that the Xen policy is not yet available in portage; I found it here:
48 http://oss.tresys.com/projects/refpolicy/browser
49
50 Good luck!
51 Richard.
52
53
54 --
55 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Xen and SElinux Fred Blaise <fred.blaise@×××××××.com>