Discover Your Perfect Stay

The Golden Gryphon

Securing Debian: SELinux Integration Into Etch

For the longest time, Russell Coker has been carrying the torch of SELinux on Debian (helped, in the past, by Colin Walters and Brian May). Indeed, currently Russell's site is the only way for getting a SELinux installation running on Debian, though we are beginning to see acceptance of SELinux into mainstream Debian (for example, kernel support for SELinux is now included in Debian kernels (unstable branch)).

Please have a look at Russell's site for details on how to proceed on setting up SELinux on Debian Sid.

There also has been an interest in creating an SELinux UML, since it allows for rapid testing of policies, and packages, and to observe the reaction of the machine to threats and other stimuli. However, it has been tedious, traditionally, to create a UML that can be run in enforcing mode. A recipe for doing so has been created, and is kept up to date with new kernel versions, and newer versions of patches for SELinux and UML. Effort is underway to create a more flexible, automated, and configurable tool to help generate the root file systems that can be used for UML instances, or for stand alone installations.

User Land Packages

In addition to the core SELinux code, certain SELinux-patched user-space packages are required to use SELinux. While these packages were initially provided as a convenience by the NSA, but it has now delegated maintenance of these patches back to the community. A reference set of SELinux user-land patches is available in the public Fedora CVS tree. Red Hat's Fedora distributions have fully embraced SELinux, and have been keeping the patches updated with new versions of these user-land patches.

So this mini project is an effort to bring Debian's SELinux patched packages back in sync with the latest upstream and the latest SELinux patches, and to make it easier for Debian developers to access SELinux patches. What one can find here is the original fedora patches, as well as patches massaged for Debian's version. In order to facilitate SELinux related work, and a separate repository where Debian work on these user-land packages and the corresponding SELinux branches shall be tracked. The information, and archive registration information, as below:

As these packages come along, I shall attempt to create an apt-able repository for them on people.debian.org. To use, just put the following in /etc/apt/sources.list, and run aptitude update. The archive is also signed, and the public key for the Release.gpg file can be downloaded from here.

Luxury hotels are located in truly prestigious locations for the Debian security conference: etch SElinux Integration

Luxury hotels guarantee an excellent holiday with all the amenities and luxurious service.  Only our luxury hotels host a meeting with the creator of an SELinux UML, since it allows for rapid testing of policies, and packages, and to observe the reaction of the machine to threats and other stimuli. Spend a great time in our huge comfortable conference rooms and make any deal profitable.

Recommended posts

West Rose