Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    cPanel, Inc. Staff
    Join Date
    Apr 2011
    Posts
    34

    Default SELinux Policy

    I'd like to see cPanel develop an official SELinux policy to allow administrators to operate their servers with SELinux turned on.

    cPanel could install this policy automatically as part of the cPanel installation process (sh latest) and keep it updated automatically as part of the cPanel update process (upcp).

    cPanel could still recommend disabling SELinux and allow each administrator to decide whether they want to enable SELinux for their machine.

    No interface would be required in WHM. The SELinux policy would be installed and updated automatically and enabling/disabling SELinux would be up to each system administrator and would be done manually on the command line.


    *** UPDATE ***

    I would like to stress that preferably this is how it would work:

    1) Installation instructions would still recommend SELinux be disabled or set to permissive
    2) Enabling SELinux would have to be enabled manually by system administrator
    3) cPanel would only support the installation of the SELinux policy and not issues with SELinux itself
    4) SELinux would require a system administrator with experience in dealing with it
    Last edited by cPanelJerrySmith; 06-22-2011 at 02:36 PM. Reason: added additional information
    Thank you,

    Jerry Smith
    Technical Analyst I
    cPanel Inc.

  2. #2
    Member monarobase's Avatar
    Join Date
    Jan 2010
    Location
    France
    Posts
    387
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: SELinux Policy

    I like the idea. Would be nice to have !

  3. #3
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,891
    cPanel/Enkompass Access Level

    Root Administrator

    Lightbulb Re: SELinux Policy

    For the uninitiated:
    SELinux can potentially control all users, processes and daemons with very precise specifications which activities are allowed for every member. However currently it is mostly used to confine daemons like database engines or web servers that have more clearly defined data access and activity rights. A confined daemon that becomes compromised is thus limited in the harm it can do. Ordinary user processes often run in the unconfined domain, not restricted by SELinux but still restricted by the classic Linux access rights.
    Security-Enhanced Linux - Wikipedia, the free encyclopedia
    Fav cPlinks this week: Blog - cPanel & WHM 11.32 we love it! | cPanel University study for it! | Attracta is coming! we want this!

  4. #4
    Member
    Join Date
    Feb 2003
    Posts
    5

    Default Re: SELinux Policy

    This is realy greate news,

    but how long you need to complete this ?

    any dead time ?


    Thank you

  5. #5
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: SELinux Policy

    Quote Originally Posted by Dellow View Post
    This is realy greate news,

    but how long you need to complete this ?

    any dead time ?


    Thank you
    That has yet to be determined as this feature still hasn't gained sufficient community support to be considered for implementation.

Similar Threads & Tags
Similar threads

  1. SELinux
    By 0101 in forum Data Protection
    Replies: 1
    Last Post: 05-18-2010, 02:47 AM
  2. Getting SELinux errors When SELinux Supposedly Disabled
    By pr0gr4mm3r in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 11-03-2008, 02:50 PM
  3. selinux
    By SACHIN in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 01-11-2007, 12:09 AM
  4. SELinux - is anyone using it with cPanel?
    By student in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 11-06-2006, 05:11 AM
  5. selinux
    By DigiCrime in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 04-05-2005, 11:14 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube