1 |
On Wed, 2008-02-13 at 18:34 +0100, atoth@××××××××××.hu wrote: |
2 |
> On Sze, Február 13, 2008 13:08, Geoff Kassel wrote: |
3 |
> > |
4 |
> > I like the idea of the SELinux per-application policies. I've never used |
5 |
> > them |
6 |
> > or SELinux, though, so I don't know how effective or simple they are to |
7 |
> > use |
8 |
> > IRL. Anyone else care to comment on this? |
9 |
> |
10 |
> Chris PeBenito is the person who probably have the most detailed knowledge |
11 |
> of SELinux here. I think it's more complex to develop a policy for an |
12 |
> application using SELinux, but a well designed framework provides |
13 |
> guidance. Targeted mode offers a chance to create a balance between |
14 |
> security and usability giving the chance for the everyday user to make use |
15 |
> of the technique without having to spend time on the policy or facing with |
16 |
> failing applications. |
17 |
|
18 |
It depends on how far you want to go. Confinement on services |
19 |
definitely is good, but for desktop applications can be problematic. In |
20 |
Gentoo we only support the targeted policy on desktops as the |
21 |
interactions between applications on the desktop vary so widely and |
22 |
people do so many unexpected things that a firefox or evolution policy, |
23 |
for example, ends up being far to restrictive for most people. |
24 |
|
25 |
-- |
26 |
Chris PeBenito |
27 |
<pebenito@g.o> |
28 |
Developer, |
29 |
Hardened Gentoo Linux |
30 |
|
31 |
Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243 |
32 |
Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243 |