SCIENTIFIC-LINUX-USERS Archives

July 2012

SCIENTIFIC-LINUX-USERS@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show HTML Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Natxo Asenjo <[log in to unmask]>
Reply To:
Natxo Asenjo <[log in to unmask]>
Date:
Tue, 10 Jul 2012 08:28:09 +0200
Content-Type:
multipart/alternative
Parts/Attachments:
text/plain (805 bytes) , text/html (1173 bytes)
On Tue, Jul 10, 2012 at 6:35 AM, Nico Kadel-Garcia <[log in to unmask]> wrote:

>
> You might also consider disabling SELinux, if the machine is behind
> reasonable firewalls. SELinux has been a *disaster* in system
> security, costing far more wasted productivity and engineering
> resources than many of active worms or attack vectors of the Linux
> world, most of which it does not really help with. (Bad PHP is bad
> PHP, and SELinux does not necessarily help at all.)
>

 let's agree to disagree on this one :-)

I have not had major issues since ... fedora 8?

It is true that selinux is a new tool and thus not so well understood by
plenty of people, but I quite like it. It is quite simple once you take the
time to learn it (like everything in life) and we routinely deploy settings
from cfengine for it.

-- 
groet,
natxo


ATOM RSS1 RSS2