|
|
|
|
|
by miah_
653 days ago
|
|
Its because Selinux wasn't really designed for "sysadmins" it was designed for "governments" or organizations that need to meet a specific level of security as a contractual/legal requirement. Selinux came out of the NSA and is based around the Trusted Systems Criteria / Common Criteria, aka the Rainbow Books. If you look at 'Trusted Solaris' (or IRIX, AIX) you'll see very similar systems. Is this poor design or simply, not designed _for_you_? I agree, its a royal pain to manage, and it might be overkill for a small shop trying to lock down their web server. Thankfully there are other solutions, and operating systems that may better fit your use cases. https://en.wikipedia.org/wiki/Common_Criteria https://en.wikipedia.org/wiki/Trusted_Solaris https://en.wikipedia.org/wiki/Security-Enhanced_Linux |
|