From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from pigeon.gentoo.org ([208.92.234.80] helo=lists.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1R0IGl-000367-3o for garchives@archives.gentoo.org; Sun, 04 Sep 2011 19:22:15 +0000 Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id AD1FA21C096; Sun, 4 Sep 2011 19:22:02 +0000 (UTC) Received: from smtp.gentoo.org (smtp.gentoo.org [140.211.166.183]) by pigeon.gentoo.org (Postfix) with ESMTP id 712E321C096 for ; Sun, 4 Sep 2011 19:22:02 +0000 (UTC) Received: from pelican.gentoo.org (unknown [66.219.59.40]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.gentoo.org (Postfix) with ESMTPS id 575381B4027 for ; Sun, 4 Sep 2011 19:22:01 +0000 (UTC) Received: from localhost.localdomain (localhost [127.0.0.1]) by pelican.gentoo.org (Postfix) with ESMTP id 75E9380042 for ; Sun, 4 Sep 2011 19:22:00 +0000 (UTC) From: "Sven Vermeulen" To: gentoo-commits@lists.gentoo.org Content-type: text/plain; charset=UTF-8 Reply-To: gentoo-dev@lists.gentoo.org, "Sven Vermeulen" Message-ID: <43499be59db77350c9b1386c6683fdd864b6a5b1.SwifT@gentoo> Subject: [gentoo-commits] proj/hardened-docs:master commit in: xml/selinux/ X-VCS-Repository: proj/hardened-docs X-VCS-Files: xml/selinux/index.xml X-VCS-Directories: xml/selinux/ X-VCS-Committer: SwifT X-VCS-Committer-Name: Sven Vermeulen X-VCS-Revision: 43499be59db77350c9b1386c6683fdd864b6a5b1 Date: Sun, 4 Sep 2011 19:22:00 +0000 (UTC) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-commits@lists.gentoo.org Content-Transfer-Encoding: quoted-printable X-Archives-Salt: X-Archives-Hash: 35fdfc0bed2b8c81e05a55bdc69749a0 commit: 43499be59db77350c9b1386c6683fdd864b6a5b1 Author: Sven Vermeulen siphos be> AuthorDate: Sun Sep 4 19:20:10 2011 +0000 Commit: Sven Vermeulen siphos be> CommitDate: Sun Sep 4 19:20:10 2011 +0000 URL: http://git.overlays.gentoo.org/gitweb/?p=3Dproj/hardened-docs= .git;a=3Dcommit;h=3D43499be5 Update on SELinux project page --- xml/selinux/index.xml | 49 +++++++++++++++++--------------------------= ------ 1 files changed, 17 insertions(+), 32 deletions(-) diff --git a/xml/selinux/index.xml b/xml/selinux/index.xml index 247963c..8cddd10 100644 --- a/xml/selinux/index.xml +++ b/xml/selinux/index.xml @@ -20,6 +20,7 @@ kernels with SELinux support, providing patches to user= land utilities, writing strong Gentoo-specific default profiles, and maintaining a good default = set of policies.

+

Security-E= nhanced Linux (SELinux) is a Mandatory Access Control system using type @@ -29,11 +30,13 @@ implementation. In addition to the kernel portion, SE= Linux consists of a library (libselinux) and userland utilities for compiling policy (checkpolicy), = and loading policy (policycoreutils), in addition to other user programs.

+

One common misconception is that SELinux is a complete security solution= . It is not. SELinux only provides access control on system objects. It can wo= rk well with other Hardened projects, such as PaX, for a more complete solution.

+ =20 @@ -65,33 +68,15 @@ As a result, we =20 pebenito -blu= eness -SwifT - - -Develop and maintain a secure, default set of policies for the system, i= ncluding -user and role definitions, service policies and application policies. - - -Develop and maintain the packages for SELinux userland utilities and lib= raries, -including SELinux-aware patches for more general applications and librar= ies. - - -Integrate, improve and maintain SELinux patches in the Linux kernel for = Gentoo -Hardened. - - -Develop and maintain SELinux documentation specific to the Gentoo distri= bution - - -Gentoo= SELinux Handbook (including installation) +blueness +SwifT + +Gentoo= SELinux Handbook (concepts, installation, maintenance) Gentoo SELinux FAQ<= /resource> - -Gentoo Hardened Roadmap= (incl. SELinux development) -Gentoo Hardened S= upport Matrices (incl. SELinux) +Gentoo Hardened Roadmap= (includes SELinux development) +Gentoo Hardened S= upport Matrices (includes SELinux) =20 Contributors @@ -128,14 +113,18 @@ be greatly appreciated.

-
Policy Submissions + +
+Policy Submissions +

The critical component of a SELinux system is having a strong policy. T= he team does its best to support as many daemons as possible. However, we = cannot create policies for daemons with which we are unfamiliar. But we are ha= ppy to receive policy submissions for consideration. There are a few requir= ements:

+
  • Make comments (in the policy and/or bug), so we can understand chang= es @@ -149,19 +138,15 @@ to receive policy submissions for consideration. T= here are a few requirements: We need to know if the policy is dependent on another policy (for ex= ample rpcd is dependent on portmap) other than base-policy.
  • -
  • - An ebuild for the policy can also be submitted to help the developer= s - integrate the policy into Portage more quickly, if it is accepted. =20 - See current daemon policies in Portage for example uses of the - selinux-policy eclass. -
+

The policy should be submitted on = bugzilla. Please attach the .te and .fc files separately to the bug, not as a tarb= all. The bug should be Cc'ed to selinux@gentoo.org and will be properl= y reassigned by the team.

+