From: Chris Wright <chrisw@osdl.org>
To: "Randy.Dunlap" <rddunlap@osdl.org>
Cc: Dave Jones <davej@redhat.com>, linux-kernel@vger.kernel.org
Subject: Re: Post-halloween doc updates.
Date: Thu, 30 Oct 2003 09:27:29 -0800 [thread overview]
Message-ID: <20031030092729.A22726@osdlab.pdx.osdl.net> (raw)
In-Reply-To: <20031030085222.3874483e.rddunlap@osdl.org>; from rddunlap@osdl.org on Thu, Oct 30, 2003 at 08:52:22AM -0800
* Randy.Dunlap (rddunlap@osdl.org) wrote:
> | SELinux.
> | ~~~~~~~~
> | NSA Security-Enhanced Linux (SELinux) got merged in 2.6.
> | It is disabled by default and can be enabled with a boot time parameter
> | selinux=1.
> | You can obtain SELinux tools and an example policy configuration from
> | http://www.nsa.gov/selinux
>
> Somebody correct me here if needed...
> selinux can't just be enabled by using 'selinux=1', if the config
> options are set for checking that.
> The way that I read security/selinux/Kconfig and hooks.c,
> if SECURITY_SELINUX_BOOTPARAM is enabled, then the 'selinux'
> boot option is also enabled. However, it can be disabled by using
> 'selinux=0' as a kernel boot option.
This is correct. SELinux defaults to not being config'd in. If you
config it in it defaults to enabled. If you also config the bootparam
you can use that param to disable it, otherwise selinux=1 is redundant
as that's the default.
thanks,
-chris
--
Linux Security Modules http://lsm.immunix.org http://lsm.bkbits.net
next prev parent reply other threads:[~2003-10-30 17:27 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-10-30 14:15 Dave Jones
2003-10-30 15:05 ` Jeff Garzik
2003-10-30 15:18 ` Dave Jones
2003-10-30 16:55 ` John Bradford
2003-10-30 15:15 ` Holger Schurig
2003-10-30 15:19 ` Dave Jones
2003-10-30 16:52 ` Randy.Dunlap
2003-10-30 17:27 ` Chris Wright [this message]
2003-10-30 18:38 ` Dave Jones
2003-10-30 18:44 ` Randy.Dunlap
2003-10-30 18:53 ` Dave Jones
2003-10-30 17:01 ` Geert Uytterhoeven
2003-10-30 19:08 ` Philipp Matthias Hahn
2003-10-30 22:16 ` bd
2003-10-31 1:32 ` Gene Heskett
2003-10-31 12:50 ` Thierry Vignaud
2003-10-30 23:11 ` Felipe Alfaro Solana
2003-10-31 0:16 ` Dave Jones
2003-10-31 2:14 ` John Levon
2003-10-31 2:30 ` Dave Jones
2003-10-31 7:34 ` ide-scsi is working [was: Post-halloween doc updates.] Nuno Silva
2003-10-31 13:42 ` Bartlomiej Zolnierkiewicz
2003-10-31 12:25 ` Post-halloween doc updates Andreas Jellinghaus
2003-10-31 15:35 ` Paul Dickson
2003-10-31 15:06 ` Ian Soboroff
2003-10-31 15:24 ` Russell King
2003-10-31 16:00 ` Aristeu Sergio Rozanski Filho
2003-10-31 16:03 ` Ian Soboroff
2003-10-31 16:14 ` Russell King
2003-10-31 17:56 ` Michael Clark
2003-11-10 23:43 ` bill davidsen
2003-11-11 1:09 ` Rob Landley
2003-11-10 14:11 ` Pavel Machek
2003-10-31 15:53 ` Ingo Oeser
2003-10-31 23:02 ` Junio C Hamano
2003-11-01 7:44 ` Sam Ravnborg
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20031030092729.A22726@osdlab.pdx.osdl.net \
--to=chrisw@osdl.org \
--cc=davej@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=rddunlap@osdl.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®