<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Strict SELinux: Can&#8217;t things be more streamlined?</title>
	<atom:link href="http://yonkeltron.com/2007/05/16/strict-selinux-cant-things-be-more-streamlined/feed/" rel="self" type="application/rss+xml" />
	<link>http://yonkeltron.com/2007/05/16/strict-selinux-cant-things-be-more-streamlined/</link>
	<description>Temporary Exile</description>
	<pubDate>Mon, 01 Dec 2008 20:33:02 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: Alberto Caso</title>
		<link>http://yonkeltron.com/2007/05/16/strict-selinux-cant-things-be-more-streamlined/#comment-7435</link>
		<dc:creator>Alberto Caso</dc:creator>
		<pubDate>Wed, 27 Jun 2007 12:30:22 +0000</pubDate>
		<guid isPermaLink="false">http://yonkeltron.com/2007/05/16/strict-selinux-cant-things-be-more-streamlined/#comment-7435</guid>
		<description>Debian Etch also uses policy modules by default.

For example, module for Apache is at /usr/share/selinux/refpolicy-strict/apache.pp and you can install it with semodule:
semodule -i /usr/share/selinux/refpolicy-targeted/apache.pp

What is left now is that every package provides its own SELinux module (or a companion package with those modules, so that there can be different modules for the same packages, for different policies). That would be great.

Regards.</description>
		<content:encoded><![CDATA[<p>Debian Etch also uses policy modules by default.</p>
<p>For example, module for Apache is at /usr/share/selinux/refpolicy-strict/apache.pp and you can install it with semodule:<br />
semodule -i /usr/share/selinux/refpolicy-targeted/apache.pp</p>
<p>What is left now is that every package provides its own SELinux module (or a companion package with those modules, so that there can be different modules for the same packages, for different policies). That would be great.</p>
<p>Regards.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Huw Lynes</title>
		<link>http://yonkeltron.com/2007/05/16/strict-selinux-cant-things-be-more-streamlined/#comment-5303</link>
		<dc:creator>Huw Lynes</dc:creator>
		<pubDate>Thu, 17 May 2007 16:16:01 +0000</pubDate>
		<guid isPermaLink="false">http://yonkeltron.com/2007/05/16/strict-selinux-cant-things-be-more-streamlined/#comment-5303</guid>
		<description>I think you are probably talking about policy modules which have already been implemented in RHEL5 and Fedora.

http://fedoraproject.org/wiki/PackagingDrafts/SELinux/PolicyModules

SElinux in redhat land has now got to the point that it usually isn't necessary to recompile SElinux policy sources on the machine. I suspect a similar approach could be taken in Debian.</description>
		<content:encoded><![CDATA[<p>I think you are probably talking about policy modules which have already been implemented in RHEL5 and Fedora.</p>
<p><a href="http://fedoraproject.org/wiki/PackagingDrafts/SELinux/PolicyModules" rel="nofollow">http://fedoraproject.org/wiki/PackagingDrafts/SELinux/PolicyModules</a></p>
<p>SElinux in redhat land has now got to the point that it usually isn&#8217;t necessary to recompile SElinux policy sources on the machine. I suspect a similar approach could be taken in Debian.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sarah Kopman-Fried</title>
		<link>http://yonkeltron.com/2007/05/16/strict-selinux-cant-things-be-more-streamlined/#comment-5245</link>
		<dc:creator>Sarah Kopman-Fried</dc:creator>
		<pubDate>Wed, 16 May 2007 22:01:56 +0000</pubDate>
		<guid isPermaLink="false">http://yonkeltron.com/2007/05/16/strict-selinux-cant-things-be-more-streamlined/#comment-5245</guid>
		<description>Dear Sir,

I have been following you very closely of late and would like to inform you that I believe you are both brilliant and most impressive.</description>
		<content:encoded><![CDATA[<p>Dear Sir,</p>
<p>I have been following you very closely of late and would like to inform you that I believe you are both brilliant and most impressive.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic Page Served (once) in 1.289 seconds -->
