Re: [gentoo-hardened] SELinux policy for nginx, or include in apache?

2011-06-21 Thread Chris Richards
On Sun, 2011-06-19 at 17:19 +0200, Sven Vermeulen wrote: On Wed, Jun 15, 2011 at 10:15:14PM -0500, Chris Richards wrote: I'm torn on this, but basically I think we ought to track upstream here. Which is... ? ;-) Well, it looked to me like Christopher pretty much squashed the patch, for

Re: [gentoo-hardened] SELinux policy for nginx, or include in apache?

2011-06-21 Thread Chris Richards
On Sun, 2011-06-19 at 17:19 +0200, Sven Vermeulen wrote: On Wed, Jun 15, 2011 at 10:15:14PM -0500, Chris Richards wrote: I'm torn on this, but basically I think we ought to track upstream here. Which is... ? ;-) Well, it looked to me like Christopher pretty much squashed the patch, for

Re: [gentoo-hardened] SELinux policy for nginx, or include in apache?

2011-06-19 Thread Sven Vermeulen
On Wed, Jun 15, 2011 at 08:40:01PM -0400, Anthony G. Basile wrote: [...] Also, we don't have policies exclusively for lighttpd. Do you know how that fits in? It's completely covered by sec-policy/selinux-apache. The httpd_t domain works pretty well with lighttpd (running it here) and contains

Re: [gentoo-hardened] SELinux policy for nginx, or include in apache?

2011-06-19 Thread Sven Vermeulen
On Wed, Jun 15, 2011 at 10:15:14PM -0500, Chris Richards wrote: I'm torn on this, but basically I think we ought to track upstream here. Which is... ? ;-) As I said, there's no clear consensus from within upstream. But I notice most people aim for a specific nginx module, so that's what we'll

[gentoo-hardened] SELinux policy for nginx, or include in apache?

2011-06-15 Thread Sven Vermeulen
Hi folks, As per bug #368795 [1] we have an open request to include a SELinux policy module for the nginx webserver. However, while working on this, I remembered a small discussion that upstream had about the same matter [2]. It boils down to the question: do we support nginx within the existing

Re: [gentoo-hardened] SELinux policy for nginx, or include in apache?

2011-06-15 Thread Francisco Blas Izquierdo Riera (klondike)
El 15/06/11 19:45, Sven Vermeulen escribió: Or do we see if we can deviate from upstream here and start our own path (in my opinion, we can't as long as we do not have a critical developer mass - in numbers, not in kilogram). Hey, I'm not that fat :P signature.asc Description: OpenPGP

Re: [gentoo-hardened] SELinux policy for nginx, or include in apache?

2011-06-15 Thread Anthony G. Basile
On 06/15/2011 01:45 PM, Sven Vermeulen wrote: So... ideas? Do we want to keep it simple and update the apache policy to support nginx? Or do we want to stay least privilege and have dedicated rules for applications? I'm only slowly coming around to policy development, but from my selinux

Re: [gentoo-hardened] SELinux policy for nginx, or include in apache?

2011-06-15 Thread Chris Richards
On Wed, 2011-06-15 at 20:40 -0400, Anthony G. Basile wrote: On 06/15/2011 01:45 PM, Sven Vermeulen wrote: So... ideas? Do we want to keep it simple and update the apache policy to support nginx? Or do we want to stay least privilege and have dedicated rules for applications? I'm