Slackware This Forum is for the discussion of Slackware Linux.


Old 01-26-2014, 08:42 AM   #1
Registered: May 2006
Posts: 58

Rep:
NSA SELinux can be turned off in kernel?

I'm running a slackware 14.1 production server. I compiled my own kernel 3.10.18. I'm seeing a bunch of these in my kernel error log:

[12891.745177] type=1401 audit(1390744778.400:3): SELinux: unrecognized netlink message type=20 for sclass=32
[12891.746369] type=1401 audit(1390744778.400:4): SELinux: unrecognized netlink message type=20 for sclass=32
[12891.747570] type=1401 audit(1390744778.400:5): SELinux: unrecognized netlink message type=20 for sclass=32

I noticed under "Security options" when compiling the kernel there is "NSA SELinux Support". Can this be turned off without impact? Account logins and passwd and PAM will all still work correct? Is there anything I need to know about this? What does it even do? Does it impact ext4 at all?

I actually get those above messages when I run /sbin/ss to see connections and whatnot. It also says
Jan 26 09:43:42 server [ 559.018776] audit_printk_skb: 12 callbacks suppressed

Thanks for any help.

uname -a:
Linux central 3.10.18 #13 SMP Sat Dec 14 15:53:39 EST 2013 x86_64 Intel(R) Xeon(R) CPU E5520 @ 2.27GHz GenuineIntel GNU/Linux

Last edited by kenw232; 01-26-2014 at 08:45 AM.
Old 01-26-2014, 09:07 AM   #2
Didier Spaier
LQ Addict
Registered: Nov 2008
Location: Paris, France
Distribution: Slackware{,64}-{14.1,current} on a Lenovo Thinkpad W520
Posts: 5,181

Rep:
NSA SELinux support is not set in Slackware kernels.

bash-4.2$ grep SELINUX config-*
config-generic-3.10.17:# CONFIG_SECURITY_SELINUX is not set
config-huge-3.10.17:# CONFIG_SECURITY_SELINUX is not set
And AFAIK PAM is not shipped in Slackware.

A bit of advice: when compiling your own kernel on Slackware, first take as a basis a config file provided by Slackware, run make oldconfig, then customize it as need be.

Last edited by Didier Spaier; 01-26-2014 at 09:09 AM.
Old 01-26-2014, 09:16 AM   #3
Registered: Sep 2009
Location: Yorks. W.R. 167397
Distribution: Slackware
Posts: 503
Blog Entries: 4

Rep:
Yes it can be turned off without impact. SELinux implements mandatory access control. It is not enabled in Slackware's own kernels.

If you are new to compiling your own kernel, it is generally better to start from a Slackware configuration (which embodies many years of wisdom and experience) and only make changes that you understand, rather than starting with the kernel's defaults (which, frankly, are quite random).
Old 01-26-2014, 10:34 AM   #4
Registered: May 2006
Posts: 58

Original Poster
Rep:
Great, thanks.


