-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
The Cost of SELinux, Audit, & Kernel Debugging
,----[ Quote ]
| Well, the area where SELinux / Audit and the debugging-enabled kernel really
| impacted the performance was with the disk and database tests (along with
| Apache). In the other Linux desktop benchmarks, there was a smaller margin,
| with some being more noticeable than the others. Disabling SELinux and Audit
| will certainly improve the performance of Fedora, while running a kernel with
| all of the debugging code enabled will cost you quite a bit in the way of
| performance. For developers, having this kernel debugging support is
| important, while for security-oriented users, having Security Enhanced Linux
| and system-call auditing support is important and worth the low cost, even
| with Intel Atom hardware.
`----
http://www.phoronix.com/scan.php?page=article&item=fedora_debug_selinux&num=1
Google File System II: Dawn of the Multiplying Master Nodes
,----[ Quote ]
| In an interview with the Association for Computer Machinery (ACM), Google's
| Sean Quinlan says that nearly a decade after its arrival, the original Google
| File System (GFS) has done things he never thought it would do.
`----
http://www.theregister.co.uk/2009/08/12/google_file_system_part_deux/
Recent:
SELinux and Security changes in the 2.6.27 Kernel
,----[ Quote ]
| # SELinux deferred mapping of filesystem contexts
| This patch by Stephen Smalley addresses the case where "alien" SELinux
| security labels need to be written to the local filesystem, for example, in
| the case of building RPMs where the local policy is different to the policy
| on the system where the RPM is to be installed. This will help with enabling
| SELinux on build systems (e.g. in the Fedora infrastructure) and more
| generally with packagers and ISVs shipping third party policy with RPMS.
`----
http://james-morris.livejournal.com/35287.html
Big Thanks To The SELinux Team
,----[ Quote ]
| I started using Fedora back in the Fedora 8 days. ÂIâve always tried to run
| SELinux in enforcing mode and back in the Fedora 8-9 days that seemed to mean
| Iâd have some SELinux issue every few days. ÂIt wasnât a big deal, but it was
| annoying and very tempting to turn it off completely.
`----
http://californiaquantum.wordpress.com/2009/06/30/big-thanks-to-the-selinux-team/
LinuxWorld preview: IBM engineer touts SELinux
,----[ Quote ]
| As SELinux adoption grows, therefore, the research-and-development challenge
| is to make it more user-friendly. "As we find issues, we'll fix them,"
| Shanker said. "We have to make it easier for the regular person to use. Once
| they learn it, they love it."
`----
http://searchenterpriselinux.techtarget.com/news/article/0,289142,sid39_gci1323731,00.html
Ubuntu gets SELinux
,----[ Quote ]
| It's official: SELinux is now available in the Ubuntu development ("Hardy
| Heron") distribution. "This is the result of the amazing work of the
| ubuntu-security and ubuntu-hardened teams, as well as the huge contributions
| from the folks at Tresys. (note: SELinux will not be the default, but is
| available as a security option.)" Installing it is a simple apt operation. Â Â
`----
http://lwn.net/Articles/273992/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAkqFVBkACgkQU4xAY3RXLo6U8QCgoWW76aWINpW3nXlDcRUmlkWc
VMsAn0e0sU9LczfuZufEjcXsW9meoRAw
=gXj0
-----END PGP SIGNATURE-----
|
|