Re: [gentoo-hardened] SELinux policy for nginx, or include in apache?

2011-06-19 Thread Sven Vermeulen
On Wed, Jun 15, 2011 at 08:40:01PM -0400, Anthony G. Basile wrote: [...] > Also, we don't have policies exclusively for lighttpd. Do you know how > that fits in? It's completely covered by sec-policy/selinux-apache. The httpd_t domain works pretty well with lighttpd (running it here) and contains

Re: [gentoo-hardened] SELinux policy for nginx, or include in apache?

2011-06-19 Thread Sven Vermeulen
On Wed, Jun 15, 2011 at 10:15:14PM -0500, Chris Richards wrote: > I'm torn on this, but basically I think we ought to track upstream here. Which is... ? ;-) As I said, there's no clear consensus from within upstream. But I notice most people aim for a specific nginx module, so that's what we'll