Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Switching hardened amd64 to SELinux
Date: Sun, 19 Feb 2012 20:51:46
Message-Id: 20120219205109.GA26094@gentoo.org
In Reply to: Re: [gentoo-hardened] Switching hardened amd64 to SELinux by "Tomáš Dobrovolný"
1 On Sun, Feb 19, 2012 at 10:07:26AM +0100, TomᨠDobrovolný wrote:
2 > I have had enabled initrd/initramfs parts in my kernel configuration,
3 > but I don't use it to boot my system. I try to disable it completely and
4 > I will see.
5
6 In that case, your /dev/console is mislabeled, and you are currently running
7 with dontaudits disabled (the many rlimitinh and other privilege attempts
8 that are by default not audited by SELinux are shown), which might cause
9 some confusion on the denials.
10
11 Relabel the system, also relabel your /dev when /dev isn't mounted (there's
12 a part about setfiles in the SELinux installation instructions just for
13 that) and enable dontaudits again (semodule -B).
14
15 Wkr,
16 Sven Vermeulen

Replies

Subject Author
Re: [gentoo-hardened] Switching hardened amd64 to SELinux "Tomáš Dobrovolný" <tomas@××××××××××.eu>