On Wed, Jun 29, 2011 at 10:07 PM, Aleksey Tsalolikhin
<atsaloli.t...@gmail.com> wrote:

> 2. https://bugzilla.redhat.com/show_bug.cgi?id=607451
>    gives an SELinux policy you could apply to filter out these messages
>    (in other words, a workaround)

good bug hunting :-)

I knew of the 2nd one (I opened it) and can confirm it works fine with
cfengine 2 and selinux in enforcing mode (rh 6.0, well, scientific
linux, to be exact).

To be honest, I no longer think about disabling selinux because it
just works for what we do. Every now and then with a new service we
have to make sure stuff keeps working, but it is a nice addition to
the security of our systems.

It has a learning curve, but that is expected of all new technologies
(just like cfengine has one :-) ).

Help-cfengine mailing list

Reply via email to