Vitavonni

Tue, 29 Nov 2005

SELinux up and running

My "test" boxes (well, they are in fact production systems) are now all up and running SELinux with a "strict" policy and in enforcing mode, after some weeks in "permissive" mode to detect the last missing policy rules (well, maybe I'm still missing something in cron.monthly?)

What took most of the time was in fact to write policy for some services or custom applications that didn't have one before. And that I basically was just checking the logs every day to see if some new audit errors had appeared. Oh, and inbetween we completely emptied the server racks and their wiring and redid the room...

Just to mention a few things that were "missing": My OpenVPN is running a custom script to update DNS on login and logout, which obviously was missing from the SELinux policy. I'm also using heartbeat to failover between the two firewalls and two mailservers; that policy took me probably one hour (without much previous experience) to write. Then I have another custom LDAP to aliases for a Lotus directory (which hopefully will be replaced by a sane application soon... whoever invented "implicite email adresses" should be shot. Just put all email adresses into the directory, so any app can look them up without trying to guess what your generation rules are... firstname.lastname@domain.tld sounds easy, but what with non-ascii characters?)

Anyway, the systems are doing pretty well. Maybe I'm going to enabled SELinux on the web server next. ( (cra-)PHP and typo3 will probably make that more difficult, though...)

Oh, and I need to sort out which of my policy changes are local changes, and which I should feed "upstream".

Menu
[planet.debian]
[planet.xmlhack]
[planet SELinux]
[munichblogs]
[email]
[RSS 2 feed]
[English RSS 2]
Categories
< November 2005 >
SuMoTuWeThFrSa
   1 2 3 4 5
6 7 8 9101112
13141516171819
20212223242526
27282930   
Archives
2010-Mar
2010-Feb
2010-Jan
2009-Dec
2009-Nov
2009-Oct
2009-Sep
2009-Aug
2009-Jul
2009-Jun
2009-May
2009-Apr
2009-Mar
2009-Feb
2009-Jan
2008-Dec
2008-Nov
2008-Oct
2008-Sep
2008-Aug
2008-Jul
2008-May
2008-Apr
2008-Mar
2008-Feb
2008-Jan
2007-Dec
2007-Nov
2007-Oct
2007-Sep
2007-Aug
2007-Jul
2007-Jun
2007-May
2007-Apr
2007-Mar
2007-Feb
2007-Jan
2006-Dec
2006-Nov
2006-Oct
2006-Sep
2006-Aug
2006-Jul
2006-Jun
2006-May
2006-Apr
2006-Mar
2006-Feb
2006-Jan
2005-Dec
2005-Nov
2005-Oct
2005-Sep
2005-Aug
2005-Jul
2005-Jun
2005-May
2005-Apr
2005-Mar
2005-Feb
2005-Jan
2004-Dec
2004-Nov
2004-Oct
2004-Sep
2004-Aug
2004-Jul
Other links:
Swing and the City - Lindy Hop in Munich