On Tue, Feb 23, Jan Engelhardt wrote:
On Tuesday 2021-02-23 22:44, Matěj Cepl wrote:
Dne 23. 02. 21 v 22:41 Thorsten Kukuk napsal(a):
[…] we also provide and use SELinux meanwhile.
Well, this seems like the optimistic declaration of the year, considering the state of our SELinux support.
1. modprobe iptable_filter 2. Declare "we're using iptables"
It's even active, not like that setenforce= option you first need in selinux ;-)
You don't need a setenforce= option for SELinux and the security=selinux option is only necessary since we patched our kernel. Else you would need a security=apparmor option. Thorsten -- Thorsten Kukuk, Distinguished Engineer, Senior Architect SLES & MicroOS SUSE Software Solutions Germany GmbH, Maxfeldstr. 5, 90409 Nuernberg, Germany Managing Director: Felix Imendoerffer (HRB 36809, AG Nürnberg)