Re: [gentoo-hardened] On the right track?

2011-11-04 Thread Anthony G. Basile
On 11/03/2011 09:44 PM, Stan Sander wrote: > I've been a unix/Linux systems administrator for over a decade, > and have been running Gentoo for at least the past 3 years. Only the first 15 years are rough. It gets easier after that. You've got 5 more to go :) Welcome! I'll let SwifT and other

Re: [gentoo-hardened] On the right track?

2011-11-04 Thread Francisco Blas Izquierdo Riera (klondike)
Welcome, pick an armchair and get confortable here near the fire. El 04/11/11 02:44, Stan Sander escribió: > I should also mention that my system runs mail, DNS, and web servers as > well as being used as my personal desktop system. Depending on your economical resources you may want to split this

Re: [gentoo-hardened] On the right track?

2011-11-04 Thread Sven Vermeulen
On Fri, Nov 04, 2011 at 07:58:45AM -0400, Anthony G. Basile wrote: > I'll let SwifT and other Selinuxers comment in detail on your policies. > I would just caution that if you keep creating policies to make every > violation disappear under all circumstanced then you're effectively > disabling sel

Re: [gentoo-hardened] On the right track?

2011-11-04 Thread Stan Sander
On 11/04/2011 12:43 PM, Sven Vermeulen wrote: > > However, if the policy is meant to be included in Gentoo, we try to follow > the style mandated by the reference policy [1], one of which includes that > the .te and .if file should never directly mention domains (like > user_home_t) if that domain