Re: [ProLinux] Apache Virtual Hosting with Fedora Core 3 and SELinux

Author: Leland Jackson

Posted: 2005-03-05 at 11:12:24

Yep, Thanks for the alert Ted. I'm not sure I like the idea of having

SELinux compiled into the kernel. I think it should be an option for a

custom compiled kernel, for those that really need that much security.

It seems like NAS is everywhere. NAS had a back door signature key,

along with Microsoft back door key that lay undiscovered and unknown,

even by Microsoft, until recently. The key had existed in windows since

early version of windows 95.

From what I've read on the web, turning on SELinux can degrade Linux

performance between 5 to 7 percent. I guess it involves process

accounting so all users on the system are tracked ever step they make,

and any mischief can then be easily traced back to the offender. I seem

strange to me that SELinux would be set to "SELINUX=enforcinfg" (eg

turned on) in the /etc/sysconfig/selinux file , or even precompiled into

the kernel for the default distribution. One explanation is that

SELinux use in FC2 was disappointing, so having it turned on by default

would increase exposure, training and use of this prototype.

At least in Linux we can download the SELinux source to have a peek, but

their is no way to be sure about the kernel that come precompiled with

SELinux from our distributors.

Regards,

LelandJ

Ted Roche wrote:

> On Mar 4, 2005, at 5:44 PM, Leland Jackson wrote:

>

>> Unless a web site need C3 security, you could just turn SELinux off

>> in FC3.

>

>

> Which can be done in several ways, as described here:

>

> http://fedora.redhat.com/docs/selinux-faq-fc3/index.html#id2825880

>

> The reason I posted was to alert others to the symptoms and problems

> they might run into when working on FC3. In this case, it ate up a lot

> of valuable classroom time.

>

> Ted Roche

> Ted Roche & Associates, LLC

> http://www.tedroche.com

>

>

>

[excessive quoting removed by server]

©2005 Leland Jackson