
On 2/12/25 11:04 AM, Cathy Hu wrote:
Hi all,
We would like to announce that with the next openSUSE Tumbleweed snapshot 20250211 the default mandatory access control (MAC) system selected by the installer will be switched from AppArmor to SELinux in enforcing mode. Additionally, the openSUSE Tumbleweed minimalVM will be shipped with SELinux in enforcing mode.
Users installing openSUSE Tumbleweed via the ISO image will see SELinux in enforcing mode as default option in the installer. If the user prefers to use AppArmor instead of SELinux, they are able to change the selection to AppArmor manually in the installer. AppArmor continues to be excellently maintained by Christian Boltz (@cboltz) exactly as before.
Existing installations using AppArmor will *not* be migrated. In case the user wishes to migrate manually to SELinux, a guide [0] is provided on the openSUSE wiki.
Hi Cathy, Congratulations on achieving your goal ! My test TW system which was manually migrated to SELinux has worked well and only had one package issue which has been fixed. When you said existing installations will *not* be migrated, did you mean will *never* be migrated unless we manually migrate them OR did you just mean that nothing is in place to migrate them right now ? -- Regards, Joe