All of lore.kernel.org
 help / color / mirror / Atom feed
From: Magnus Therning <magnus-work@therning.org>
To: selinux@tycho.nsa.gov
Subject: Re: SELinux on Debian (Sid)
Date: Thu, 10 Jun 2004 14:03:44 +0200	[thread overview]
Message-ID: <20040610120344.GM5477@philips.com> (raw)
In-Reply-To: <200406101817.28861.russell@coker.com.au>

[-- Attachment #1: Type: text/plain, Size: 2732 bytes --]

I forgot to mention the contents of my /etc/apt/sources.list:

 deb http://ftp.uk.debian.org/debian/ testing main non-free contrib
 deb http://ftp.uk.debian.org/debian-non-US testing/non-US main contrib non-free

 deb http://ftp.uk.debian.org/debian/ unstable main non-free contrib
 deb http://ftp.uk.debian.org/debian-non-US sid/non-US main contrib non-free

 deb http://www.coker.com.au/newselinux/ ./

This together with the following line in /etc/apt/apt.conf should give
me a Sid system:

 APT::Default-Release "unstable";

I did a 'apt-get update' and a 'apt-get dist-upgrade' after this.

On Thu, Jun 10, 2004 at 06:17:28PM +1000, Russell Coker wrote:
>On Thu, 10 Jun 2004 00:44, Magnus Therning <magnus-work@therning.org> wrote:
>> Installing selinux-default-policy failed, make complains about
>> 'chsid' not being present. These are the problems I run into when
>> trying to complete the installation of the policies:
>
>Sounds like you have old SE Linux, that is ancient and no longer being
>supported.  It is only supported to kernel 2.4.21 upstream and 2.4.22
>on my web site (in the section that is no longer maintained).  I
>strongly recommend the new SE Linux.

The selinux-default-policy came from the apt-repository mentioned above.

My initial attempt to get things working was a few weeks ago, and then I
had even more problems, that time with the Makefile not being able to
handle the output from 'checkpolicy' (a cut -f 1 -d ' ' was needed).
This was apparently fixed.

>>  3. 'make relabel' fails on a standard kernel:
>>
>>       load_policy: security_load_policy failed
>>
>>     After rebooting using my SE-kernel 'make relabel' also fails:
>>
>>       security:  policydb magic number 0x8 does not match expected magic
>> number 0xf97cff8c load_policy: security_load_policy failed
>
>Sounds like you have new SE Linux in the kernel and old SE Linux in the
>utilities.  Don't use the packages in woody.  Start with Brian's
>back-ports if you want to use SE Linux in woody, but they haven't been
>maintained for a while either.  It's best to use Debian/unstable (the
>next version of Debian will be out soon so there seems little point in
>starting with the old version now).

Again all packages come from your repository.

I'll take a look at it again later today, to see if there has been any
new packages uploaded since my last attempt.

/M

-- 
-----------------------------------------------------------------------
Magnus Therning                 Philips Research Laboratories Eindhoven
Phone: +31 40 2745179           (OpenPGP: 0x4FBB2C40)

Certum est, quia impossibile. (It is certain, because it is impossible.)
     -- Tertullianus

[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

  reply	other threads:[~2004-06-10 12:04 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-06-09 14:44 SELinux on Debian (Sid) Magnus Therning
2004-06-09 17:50 ` Luke Kenneth Casson Leighton
2004-06-10  8:13   ` Russell Coker
2004-06-10 22:04     ` Luke Kenneth Casson Leighton
2004-06-10 12:09   ` Magnus Therning
2004-06-10 21:46     ` Luke Kenneth Casson Leighton
2004-06-10  8:17 ` Russell Coker
2004-06-10 12:03   ` Magnus Therning [this message]
2004-06-10 13:53     ` Russell Coker
2004-06-10 21:54     ` Luke Kenneth Casson Leighton
2004-06-11  4:13       ` Russell Coker
2004-06-11 20:40         ` Luke Kenneth Casson Leighton
2004-06-12  2:11           ` Russell Coker
2004-06-12  8:14             ` Luke Kenneth Casson Leighton
2004-06-12  8:15             ` Luke Kenneth Casson Leighton
2004-06-11 23:26         ` Greg Norris
2004-06-12  8:19           ` Russell Coker
2004-06-12 14:37             ` Greg Norris
2004-06-13  0:29               ` Russell Coker
2004-06-13  1:28                 ` Greg Norris
2004-06-13  7:54                   ` Luke Kenneth Casson Leighton
2004-06-13 15:40                     ` Greg Norris
2004-06-13 16:03                       ` Greg Norris
2004-06-13 23:26                         ` Greg Norris
2004-06-14  3:39                           ` Greg Norris
2004-06-14 11:38                             ` Russell Coker
2004-06-14 12:31                               ` Greg Norris
2004-06-18 19:01                             ` Luke Kenneth Casson Leighton
2004-06-13 18:29                       ` Luke Kenneth Casson Leighton

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20040610120344.GM5477@philips.com \
    --to=magnus-work@therning.org \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.