SELinux

Tim ignored_mailbox at yahoo.com.au
Fri Jun 9 12:23:26 UTC 2006


On Fri, 2006-06-09 at 14:14 +0200, Derek Jander wrote:
> Which level of SELinux you recommend for a personal laptop? I mean, if
> you are not offering any service to internet or you don't have many
> users and stuff is it really necessary?

Enforcing does what the label says, enforces the rules.  (Presuming that
no-one's goofed...  It's never a good idea to place absolute trust in
something.)

Permissive does what it says, it permits it.  It offers you no
protection, lets you do what you tried to, but gives you a report about
it.  Which would then allow you to design custom rules, or modify your
software not to do things it shouldn't, if you understood such things.

Off, does nothing at all.

If you want it, use enforcing.  If you're programming or going to fix
things, you'd probably want it on, but would switch to permissive while
fixing things up.  If you don't want it, turn it off.

-- 
(Currently running FC4, in case that's important to the thread)

Don't send private replies to my address, the mailbox is ignored.
I read messages from the public lists.




More information about the fedora-list mailing list