On 11/03/2011 09:44 PM, Stan Sander wrote:
> I've been a unix/Linux systems administrator for over a decade,
> and have been running Gentoo for at least the past 3 years.
Only the first 15 years are rough. It gets easier after that. You've
got 5 more to go :) Welcome!
I'll let SwifT and other Selinuxers comment in detail on your policies.
I would just caution that if you keep creating policies to make every
violation disappear under all circumstanced then you're effectively
disabling selinux. So you need to examine the consequence of each rule
as you are doing, or asking us to do, which is good.
@SwifT - did you ever migrate that doc on how to debug policies to the tree?
Don't be afraid to open bugs as I said in my earlier @newbie email.
As far as the rest of your system, you'll probably want to understand
kernel and toolchain hardening as well:
http://www.gentoo.org/proj/en/hardened/
In brief:
kernel hardening = emerge hardened-sources and enable grsec/pax
grsec = turning off certain operations which can be insecure
(eg. mounting within chroots to break chroots)
pax = enforcing constraints on allocated memory
grsec also provides its own MAC system (RBAC) which you cannot have
enabled at the same time as selinux.
toolchain hardeneing = swtich to hardened profile as you have, re-emerge
gcc/glibc/binutils, re-emerge @system then @world
= ssp = protection against classic buffer overflows
= pie = helps randomize process address space
= fortify-sources = tighten up glibc
--
Anthony G. Basile, Ph.D.
Gentoo Linux Developer [Hardened]
E-Mail : [email protected]
GnuPG FP : 8040 5A4D 8709 21B1 1A88 33CE 979C AF40 D045 5535
GnuPG ID : D0455535