Gentoo Archives: gentoo-hardened

From: Robert Sharp <selinux@×××××××××××××××.org>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] SELinux and rkhunter
Date: Fri, 25 Nov 2016 14:02:03
Message-Id: 6a717115-eb2a-7e01-b866-e0fa6a917dc1@sharp.homelinux.org
In Reply to: Re: [gentoo-hardened] SELinux and rkhunter by Jason Zaman
1 On 25/11/16 11:51, Jason Zaman wrote:
2 > Ideally, rkhunter should just have a policy.
3 > It would need something like: cron_system_entry(rkhunter_t, rkhunter_exec_t)
4 > If you wanted to write one, basing it off the aide policy would probably
5 > help.
6 > https://gitweb.gentoo.org/proj/hardened-refpolicy.git/tree/policy/modules/contrib/aide.te
7 > Its quite a simple policy, it pretty much just needs to read everything
8 > on disk.
9
10 Well, I want to learn more about SELinux so writing and testing a
11 "proper" policy sounds like an idea. I will give it a go.
12
13 Robert

Replies

Subject Author
Re: [gentoo-hardened] SELinux and rkhunter Sven Vermeulen <swift@g.o>