Author: Leland Jackson
Posted: 2005-03-05 at 12:21:24
Hi Ed,
When I installed FC2 on my desktop, I choose to install the entire ball
of wax, so I could take a look at everything and stay abreast of all
changes. If SELinux was an install option in FC2, it must have install
like like MySQL, Apache httpd, NIS, etc, as a separate module, opposed
to being compiled into the kernel. If I understand it correctly, NAS
was/is doing a proof of concept in run SELinux as a part of the basic
kernel, to see if it can be done without degradation to the overall
system, and to see just how effective this kind of software can be
handled within the kernel, so if I installed the default FC3 kernel, or
accept "up2date" yum kernel releases, I will be stuck with SELinux;
whether I want/need it or not. This is a little troubling to me.
We are eventully going to be stuck with NAS anyway, as the tools needed
to intrude systems and protect aginst intruders are moving towards being
embedded in the computer's CPU and other motherboard chips that make up
the hardware.
Regards,
LelandJ
Ed Leafe wrote:
> On Mar 5, 2005, at 11:12 AM, Leland Jackson wrote:
>
>> I'm not sure I like the idea of having SELinux compiled into the
>> kernel. I think it should be an option for a custom compiled kernel,
>> for those that really need that much security.
>
>
> Dunno about FC3, but when I installed FC2, it gave me the option
> to include it or not.
>
> ___/
> /
> __/
> /
> ____/
> Ed Leafe
> Come to PyCon!!!! http://www.python.org/pycon/2005/
>
>
>
[excessive quoting removed by server]