LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-11-2011, 03:30 AM   #1
JonJAN
LQ Newbie
 
Registered: Aug 2011
Posts: 10

Rep: Reputation: Disabled
Few questions about SElinux


I intent to start using fedora for that extra boost of security. I did some reading but I lost in the complexity of the SElinux.

If I understood correctly, audit2allow will allow whatever that program wants, which does not sound very secure. But I don't (yet) have the skill to manually edit the SE rules, so I will end up using it alot.

>First question is, do you think "linux+SElinux+(lots of allow2audited software)" will make a worse security than plain linux?

>I know third party repos aren't security wise but I need mp3 and unrar from rpmfusion. What will happen if stuff I downloaded comes without any sepolicy, will selinux allow it wreak havoc or block it completely?

> What do you thinkg about fedora gui tools for policy management?
 
Old 08-11-2011, 10:48 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by JonJAN View Post
If I understood correctly, audit2allow will allow whatever that program wants, which does not sound very secure. But I don't (yet) have the skill to manually edit the SE rules, so I will end up using it alot. >First question is, do you think "linux+SElinux+(lots of allow2audited software)" will make a worse security than plain linux?
SELinux (Mandatory Access Controls) works on top of DAC (Discretionary Access Controls aka "ownership and permissions") so MAC can only enhance security. Regardless of that reviewing rules before using them should be done. Just post them if unsure.


Quote:
Originally Posted by JonJAN View Post
>I know third party repos aren't security wise but I need mp3 and unrar from rpmfusion. What will happen if stuff I downloaded comes without any sepolicy, will selinux allow it wreak havoc or block it completely?
MP3 OK but I do not know of *any* Free or Open Source Software that requires RAR to unpack. (Commonly the compression format is associated with warezed stuff so if you don't do illegal or shady D/Ls then you wouldn't need it anyway. Regardless of that discussion there is a "p7zip-rar" extraction module for the p7zip package.) Default "targeted" SELinux policy is a kind of "outside-in" policy: providing an extra layer of hardening for running (networked) services but leaving local users free to run things (or "unconfined" in SELinux-speek). Hence you wouldn't have any problems running that kind of software unless it tries to access entities restricted by the policy. In that case creating rules and reviewing them carefully before using them may alleviate trouble.


Quote:
Originally Posted by JonJAN View Post
> What do you thinkg about fedora gui tools for policy management?
I have no opinion as as I prefer the command line and only a GUI tool to create policies for new services.
 
1 members found this post helpful.
Old 08-11-2011, 02:17 PM   #3
JonJAN
LQ Newbie
 
Registered: Aug 2011
Posts: 10

Original Poster
Rep: Reputation: Disabled
Thanks that was the most helpful post ever!

I'm definitely going to SElinux.
Can you advice me a good reading to get me started?
How long does it takes to learn selinux?
 
Old 08-11-2011, 05:33 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by JonJAN View Post
Can you advice me a good reading to get me started?
Actually the Fedora website has SELinux pretty much documented well: index, FAQ and the Fedora SELinux User Guide. Do read but don't try to take it all in: pace things, look them up as you go slash need answers.


Quote:
Originally Posted by JonJAN View Post
How long does it takes to learn selinux?
Heh, I'm not the right person to ask. I haven't mastered it and I only know what I need to know (OK, a *wee* bit more ;p).
 
Old 08-12-2011, 03:08 AM   #5
JonJAN
LQ Newbie
 
Registered: Aug 2011
Posts: 10

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by unSpawn View Post
I only know what I need to know (OK, a *wee* bit more ;p).
actually that is the very level of mastery I'm targeting.
 
Old 08-15-2011, 11:59 PM   #6
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,359

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
You should find chap 43 here pretty comprehensive http://www.linuxtopia.org/online_boo...ion/index.html
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SELinux errors, SELinux and wine ziphem Linux - Security 10 01-27-2011 04:15 PM
Selinux-how do i find out what domains have permissions on what type?(selinux policy) vishyc88 Linux - Security 2 11-22-2010 04:27 AM
Questions regarding the selinux? linuxunix Linux - Newbie 2 05-05-2010 12:39 AM
Questions about SELinux TheStarLion Linux - Security 16 12-02-2009 04:42 PM
Questions about selinux on slackware okos Slackware 16 12-13-2008 04:04 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:22 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration