10 things you probably did not know about SELinux.. #3
SELInux versus nsswitch.confMany confined domains call getpwnam, getpwuid, getpwent functions. Traditionally these function calls just read the the /etc/passwd file. In a modern Linux system the...
View Article10 things you probably did not know about SELinux.. #4
#4 How do I tell whether a domain is confined on an SELinux System?On SELinux targeted systems, we have confined domains and unconfined domains, and as of RHEL6 and all supported Fedoras we also have...
View ArticleI will be presenting SELinux at Boston Securty Meetup Tonight.
http://www.meetup.com/boston-security-meetup/events/16738054/
View Article10 things you probably did not know about SELinux.. #5
#5 How do I add new file systems/disks to an SELinux machine?Lets examine three use cases:1: You just got back from Best Buy with a brand new 100 Gig Disk that you want to mount on /home and store your...
View Article10 things you probably did not know about SELinux.. #6
#6 How did those SELinux labels get there?SELinux labels are placed on disk during the installation by a combination of Anaconda and rpm. Anaconda actually includes the latest...
View ArticleSELinux Policy RPM in Rawhide/F16 includes prebuilt policy file.
The selinux-policy-TYPE packages has always rebuilt the policy in their post install. We do this in order to merge any customizations to the policy that an administrator might have made. The selinux...
View Article10 things you probably did not know about SELinux.. #7
#7 Does an SELinux Audit Log message always mean something was blocked? NOFirst off lets get rid of a misconception. An SELinux AVC message consist of a single message in the audit log. This is...
View ArticleFollow up to #7 Does an SELinux Audit Log message always mean something was...
In my previous blog10 things you probably did not know about SELinux.. #7I stated that one of the times you can get a syscall to succeed even though AVC's were generated was:3. An AVC was generated but...
View ArticleFun with sVirt.
I have been in Washington DC for the last few days talking about SELinux and sVirt, Secure Virtualization. sVirt is the combining of SELinux with kvm/qemu virtualization. The libvirt daemon launches...
View ArticleNew Kiosk OS posted for Fedora 15
Thanks to Miroslav Grepl, he has put together a working Kiosk OS for Fedora 15.http://people.fedoraproject.org/~dwalsh/SELinux/kiosk/ Name Last modified Size Parent Directory - kiosk.iso 12-Jul-2011...
View ArticleA new short video starring yours truly available to RHEL subscribers.
New SELinux Features in Red Hat Enterprise Linux 6The Red Hat Video Team did a great job in attempting to make this old guy look good. :^)Check it out...
View ArticleFedora 16 is about to go to Alpha release, some SELinux changes.
First with the move to systemd, we were asked to move the /selinux file system to a more standard location.From this point forward the selinuxfs will be mounted under /sys/fs/selinux.This seems to be...
View ArticlesVirt to the Rescue
At the recent Black Hat conference Nelson Elhage presented:Virtualization Under Attack: Breaking out of KVMThe exploit, CVE-2011-1751, would allow a cracker to execute code in qemu-kvm process on the...
View ArticleFedora 16 Alpha available part II, New SELinux Feature/File Name Transitions
Fedora 16 Alpha was just released:The announcement include the following: SELinux Enhancements. SELinux policy package now includes a pre-built policy that will only rebuild policy if any...
View ArticleFedora 16 Alpha available, New SELinux Feature/Prebuilt Policy.
Fedora 16 Alpha was just released: The announcement include the following: SELinux Enhancements. SELinux policy package now includes a pre-built policy that will only rebuild policy if any...
View ArticleFedora 16 Alpha available part II, New SELinux Feature/File Name Transitions
Fedora 16 Alpha was just released: The announcement include the following: SELinux Enhancements. SELinux policy package now includes a pre-built policy that will only rebuild policy if any...
View ArticleFedora 16 New SELinux Feature part III - permissivedomains module
As has been stated in previous blogs we have three types of unconfined processes on Fedora. We have unconfined_domain() system processes. initrc_t, init_t, kernel_t, ...We have unconfined_domain()...
View ArticleFedora 16 New SELinux Feature part IV - Shrinking policy
Back in July the systemd team was trying to decrease the boot time on early versions of Fedora 16. They found that with a Solid State disk, SELinux policy load and relabel was quickly becoming the...
View Articlesetrans is a handy little tool to analyze policy transitions
For several years we have had a SELinux tool set called setools that allows you to analyse policy. I use sesearch and seinfo all the time for looking at policy. setools includes a tcl/tk interface,...
View ArticleMaking a domain "unconfined"
In a couple of previous blogs I talked about permissive and unconfined domains.http://danwalsh.livejournal.com/24537.html?thread=176857http://danwalsh.livejournal.com/42394.htmlToday we had a question...
View Article