selinux -- or is it

Daniel J Walsh dwalsh at redhat.com
Thu May 8 17:36:18 UTC 2008


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

g wrote:
> Daniel J Walsh wrote:
>> touch /.autorelabel
>> reboot
> 
> ok, '/.autorelabel' was there. it was there from install.
> 
> i did 'touch' it again to put new date on it. i did not boot into f8, as
> 
> i did not know what state to have selinux in. now that i know how easy it
> is to disable selinux, which level should i put it in, 'enforcing' or
> 'permissive'?
> 
> [btw. i will not discuss how to easily disable selinux on this or any list.
>  nor do i believe it should be. no need to make it easy for system hackers.
>  if it has been told, please do not blame me just because i mentioned it.]
> 
> 
If you are using reiserfs, then you should not use SELinux.  It does not
support extended attributes properly.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkgjOhIACgkQrlYvE4MpobPIuQCfdwSxkVp/OePPDFIpO920Mjfs
UFUAoIPs0gOrjIBIAjVyC+jOr9yaE/DY
=4xqW
-----END PGP SIGNATURE-----




More information about the fedora-list mailing list