[selinux] Re: State of SELinux today in openSUSE?

Hi, On Tue, Nov 17, Neal Gompa wrote:
I'm personally looking to switch my openSUSE servers and desktops to having SELinux enabled in enforcing mode with the targeted policy, and I'm happy to help wherever I can to make that work. My personal pie-in-the-sky hope is that we can be in a place soon where we could be comfortable with having it as a default across the board (even if we might not necessarily do so).
Tumbleweed: Install the selinux pattern, add "security=selinux selinux=1" to the kernel commandline, touch /.autorelabel and reboot. Yes, YaST support and documentation is still missing.
I know right now the focus has been to get the targeted policy working in openSUSE MicroOS, do we know what's left here to make this happen?
Don't install apparmor pattern but selinux pattern, make sure you are really "current": - transactional-update >= 2.28.3 - microos-tools >= 2.9 Run "transactional-update setup-selinux" and reboot. And yes, YaST support and documentation is still missing... Thorsten -- Thorsten Kukuk, Distinguished Engineer, Senior Architect SLES & MicroOS SUSE Software Solutions Germany GmbH, Maxfeldstr. 5, 90409 Nuernberg, Germany Managing Director: Felix Imendoerffer (HRB 36809, AG Nürnberg)

On Tue, Nov 17, 2020 at 08:27:57PM +0100, Thorsten Kukuk wrote:
On Tue, Nov 17, Neal Gompa wrote:
I'm personally looking to switch my openSUSE servers and desktops to having SELinux enabled in enforcing mode with the targeted policy, and I'm happy to help wherever I can to make that work.
The main thing currently is testing. We need as many different configurations as possible to use the current policy to figure out where we're still missing adjustment
My personal pie-in-the-sky hope is that we can be in a place soon where we could be comfortable with having it as a default across the board (even if we might not necessarily do so).
Tumbleweed: Install the selinux pattern, add "security=selinux selinux=1" to the kernel commandline, touch /.autorelabel and reboot.
There are still some issues around graphical logins for me on Tumbleweed where I need time to investigate. Leap 15.2 works flawlessly for me ATM. Johannes -- GPG Key E7C81FA0 EE16 6BCE AD56 E034 BFB3 3ADD 7BF7 29D5 E7C8 1FA0 Subkey fingerprint: 250F 43F5 F7CE 6F1E 9C59 4F95 BC27 DD9D 2CC4 FD66 SUSE Software Solutions Germany GmbH, Maxfeldstr. 5, 90409 Nuernberg Geschäftsführer: Felix Imendörffer (HRB 36809, AG Nürnberg)
participants (2)
-
Johannes Segitz
-
Thorsten Kukuk