Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: SElinux for debian
PostPosted: Sat Oct 22, 2011 6:04 pm 
Offline

Joined: Wed Jul 06, 2011 11:09 pm
Posts: 1
Anybody knows how to enable SElinux in default linode kernel for debian


Top
   
 Post subject:
PostPosted: Sat Oct 22, 2011 7:11 pm 
Offline
Senior Member
User avatar

Joined: Sat Aug 30, 2008 1:55 pm
Posts: 1739
Location: Rochester, New York
Short answer: you don't, because SELinux is a compile-time option and is disabled by default in Linode kernels (for compatibility with non-SELinux userlands).

This will let you run Debian's own SELinux kernel:
http://library.linode.com/linode-platfo ... grub-howto

_________________
Code:
/* TODO: need to add signature to posts */


Top
   
 Post subject:
PostPosted: Sat Nov 19, 2011 11:49 pm 
Offline
Senior Newbie

Joined: Wed Aug 10, 2011 10:06 pm
Posts: 12
Website: http://helpher.net
Hoopycat.

I just followed instructions at http://library.linode.com/linode-platfo ... grub-howto and followed instructions http://wiki.debian.org/SELinux/Setup here, I was getting some avc error messages in syslog which i have handled using audit2allow.

in the linode instructions it said do

apt-get install linux-image-xen-686 ,

and in the new linode profile it says (pv-grub-x86_32) .

Is (pv-grub-x86_32 something that will be updated by linode? I am a bit unsure about updating the kernel in general especially in the context of linode considering we have to follow special instructions as above in the first place. EDIT>> reading again it seems that upgrades would be down to me. If I did an upgrade would that break the selinux settings?


Also , Everything seems to work fine at the moment but I could anticipate something going wrong later on judging by some discussions of selinux I have seen. if that were the case then if I booted into the original profile kernel would I lose any configuration settings?[/url]

_________________
helpher.net


Top
   
 Post subject:
PostPosted: Sun Nov 20, 2011 1:58 pm 
Offline
Senior Member
User avatar

Joined: Sat Aug 30, 2008 1:55 pm
Posts: 1739
Location: Rochester, New York
marcl wrote:
Is (pv-grub-x86_32 something that will be updated by linode?


Yes, but all pv-grub does is boot a kernel that is located within your disk image. It's analogous to the BIOS on your computer. It probably won't be updated unless it absolutely has to be, since it works and has few security implications.

Quote:
I am a bit unsure about updating the kernel in general especially in the context of linode considering we have to follow special instructions as above in the first place. EDIT>> reading again it seems that upgrades would be down to me. If I did an upgrade would that break the selinux settings?


It's up to you to keep the kernel updated, and any time something changes, there's the potential for something to break.

However, since you've chosen to let Debian handle that, so updates will be provided with your usual APT upgrades, and they probably won't break things. Delegating the responsibility isn't a bad idea here.

Quote:
Also , Everything seems to work fine at the moment but I could anticipate something going wrong later on judging by some discussions of selinux I have seen. if that were the case then if I booted into the original profile kernel would I lose any configuration settings?[/url]


I'm not too familiar with SELinux, but I'd suspect the userland parts of it will fail gracefully when they realize the kernel doesn't support SELinux. Worth a test, I suppose.

_________________
Code:
/* TODO: need to add signature to posts */


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group