-
Notifications
You must be signed in to change notification settings - Fork 25
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[QUESTION] Default policies already deployed when "selinux" pkg group is installed? #126
Comments
Hello,
I am maintaining 3 packages related to refpolicy (https://github.com/SELinuxProject/refpolicy):
To use For your 3rd question,
I don't know. You could take a look at https://github.com/SELinuxProject/refpolicy By the way, I am aware that
I don't remember of an automation like Sorry for not answering more precisely. Due to the end-of-year holidays I am currently away from my usual SELinux testing infrastructure and will not be able to really work on things until beginning of January. If you have other questions, feel free to add more. |
I am following https://wiki.archlinux.org/title/SELinux to install SELinux on my Arch environment.
I installed all selinux tools by installing
selinux
pkg group. By following Arch Wiki, at https://wiki.archlinux.org/title/SELinux#Installing_a_policy , it explains how to build and deploy the default policies (/etc/selinux/refpolicy/policy
).My 1st question: when I install
selinux
pkg group, the default SELinux policies stored in/etc/selinux/refpolicy/src/policy/
are already automatically deployed or I need to build and install them afterselinux
pkg group install?My 2nd question: on
/etc/selinux/config
I seeSELINUXTYPE=refpolicy-arch
and in/etc/selinux/
I see:refpolicy
has asrc
directory where I build, install and load bymake
the default policies. Once loaded, if I haveSELINUXTYPE=refpolicy-arch
in myconfig
and I reboot the system and I runrestorecon -r /
, arerefpolicy
removed andrefpolicy-arch
automatically applied?My 3rd question: in https://wiki.archlinux.org/title/SELinux#Installing_a_policy when deal with the creation of
requiredmod.te
file with the following content:and run the commands:
"to remove a few messages from /var/log/audit/audit.log which are a nuisance to deal with in the reference policy", is it already done by these refpolicy-arch (so we don't need to do this hacky stuff) or not?
My 4th question: after the install of
selinux
pkg group, do I still need to label the entire filesystem byrestorecon -r /
or it is already automatically done?The text was updated successfully, but these errors were encountered: