Add new comment

Want to support HowtoForge? Become a subscriber!
Submitted by Anonymous (not registered) on Fri, 2008-12-05 12:38.

Personally, I think it's a little naughty on your part to suggest disabling SE-Linux by default. As was very recently demonstrated, the very source of updates (which are, of course, necessary for a secure system - a static, un-updated system is by definition not a secure system) may be taken off-line by a malicious attack. When that happens, there is little beyond SE-Linux to guarantee a safe and secure system until such time as upstream updates are restored. This can, as has been recently demonstrated, take a not insignificant amount of time.

 Instead, you should be suggesting that the user retain SE-Linux (as is the default for Fedora, and should require no explicit action on part of the user) and use the SE-Linux Trouble-shoot tool to interact via bugzilla with the Fedora team to adequately handle any edge-cases that may be omitted for very specific scenarios that the user may experience.

 As many "newbies" read and follow your instructions, you have a moral obligation to keep the uninitiated user as secure as possible.

Please do not use the comment function to ask for help! If you need help, please use our forum.
Comments will be published after administrator approval.

Reply

*
*
The content of this field is kept private and will not be shown publicly.


*

  • Images can be added to this post.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <img> <div>
  • Lines and paragraphs break automatically.