Home Messages Index
[Date Prev][Date Next][Thread Prev][Thread Next]
Author IndexDate IndexThread Index

[News] SELinux is Not Hard, But Hardened

  • Subject: [News] SELinux is Not Hard, But Hardened
  • From: Roy Schestowitz <newsgroups@xxxxxxxxxxxxxxx>
  • Date: Tue, 02 Oct 2007 00:15:41 +0100
  • Newsgroups: comp.os.linux.advocacy
  • Organization: Netscape / schestowitz.com
  • User-agent: KNode/0.10.4
Tip of the Trade: SELinux  

,----[ Quote ]
| You don't need to be a super-guru to set up a workable SELinux policy, just 
| an ordinary, diligent server administrator unafraid to read a bit of  
| documentation. 
`----

http://www.serverwatch.com/tutorials/article.php/3702626

Linux Application Hardening

,----[ Quote ]
| When we talk about Linux hardening, we typically mean runtime 
| application hardening to improve application reliability, leading to expected 
| and predictable execution despite undesirable operating conditions (such as 
| high memory or network overload).    
`----

http://opensource.sys-con.com/read/431838_p.htm


Related:

SELinux — is it really too complex?

,----[ Quote ]
| What I discovered is that part of SELinux’s current dilemma is more easily 
| fixable than the other, because it has nothing to do with technological chops 
| and everything to do with public perception. Jim Klein, the director of 
| information services and technology at the California-based Saugus Union 
| School District, put it best: “The biggest problem for SELinux is mindshare,”  
| Klein told me. “It developed a stigma early on due to the lack of tools for 
| configuration and troubleshooting, which led people to simply turn it off.” 
| Currently, Klein is one of the many IT guys who has the SELinux switch in 
| the “off” position.       
`----

http://enterpriselinuxlog.blogs.techtarget.com/2007/09/26/selinux-is-it-really-too-complex/


SELinux vs. OpenBSD's Default Security

,----[ Quote ]
| Darrin Chandler suggested, "security should not be grafted on, it should be 
| integrated into the main development process. I'm sure the patch maintainers 
| are doing their best, but this doesn't change the fundamental flaw in the 
| process. It's not a flaw of their making, it's inherent in the situation. But 
| it's still a flaw."    
`----

http://kerneltrap.org/OpenBSD/SELinux_vs_OpenBSDs_Default_Security

[Date Prev][Date Next][Thread Prev][Thread Next]
Author IndexDate IndexThread Index