On Sun, 2005-10-23 at 13:54 -0400, Dale Pontius wrote:
> I decided to remove it and install syslog-ng. That appeared to work at 
> first. But as far as I can tell, nothing has been logged since the first 
> time I put the systeminto enforcing mode.

Need to see some denials to better understand whats going on.

> 2: Can't ssh in when the system is enforcing. I've checked the sestatus 
> -v results, and everything looks ok. I've never seen a bogus console or 
> log message, but then again, see (1). Here's what I get:
> [EMAIL PROTECTED] ~ $ ssh -v [EMAIL PROTECTED]

Again, need to see some denials on the server, and logs from sshd if
they have anything interesting other than the failed login message.

> 3: There isn't much about "standard practice".
> What kinds of admin tasks can I perform while the system is enforcing?
> What kinds of admin tasks do I have to drop out of enforcing for?

The goal is to always enforce.  Ideally, you should never have to switch
to permissive to do admin tasks.

> I presume emerging a new policy requres "make load". What requires "make 
> relabel"?

You should generally relabel after switching from permissive back to
enforcing.  That may also mean restarting if processes aren't in the
right context.  Other than that, you shouldn't need a complete relabel
except in recovery type situations.  Or massive policy changes.

> What about things that don't have a policy? Like dovecot, leafnode, etc?
> On my old system I ran things chroot'ed. Can I still, under SELinux?

Our policy is a little stagnant, since the NSA example policy will be on
its way out, and we will be switching to Reference Policy
(http://serefpolicy.sf.net/) when its ready in a couple months.  It will
be a significanly easier policy to manage and develop.  It'll also bring
along with it the targeted policy, for desktops.

You can run stuff chrooted, but it will likely require extra policy work
to get things labeled right.  Though, with a good MAC system like
SELinux, the usefulness of chroot is questionable.

-- 
Chris PeBenito
<[EMAIL PROTECTED]>
Developer,
Hardened Gentoo Linux
Embedded Gentoo Linux
 
Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
Key fingerprint = B0E6 877A 883F A57A 8E6A  CB00 BC8E E42D E6AF 9243

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to