|
|
|
|
|
by sliken
3483 days ago
|
|
I think the main problem is that it's too much of a pain. Seems like whenever I configure DHCP, Bind, Postfix, Mysql, or other popular daemons, as soon as I get into a non-trivial configuration I start getting SElinux complaints. Sure I can track them down and fix them, but there's only so much I'm willing to do. Seems like what SELinux should do is read the same config file the daemon does. That way when a distro makes changes to the filesystem layout that SElinux gets a free ride. After all on a well run system there should be exactly one place for any single piece of important information, not two. |
|
That means we do have to write some of these things down twice, because we want to have a fence and a lawn.