From: Timothy <timothy@diyab.net>
To: Stephen Smalley <sds@tycho.nsa.gov>
Cc: Lee Lowder <friedbob@sbcglobal.net>, selinux@tycho.nsa.gov
Subject: Re: Getting started with SELinux and Slackware
Date: Thu, 22 Sep 2005 14:02:29 -0400 [thread overview]
Message-ID: <4332F1B5.2010704@diyab.net> (raw)
In-Reply-To: <1127392107.19487.23.camel@moss-spartans.epoch.ncsc.mil>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
All of the modified slackware sources that I used to build that old
release are available on that ftp site (ftp.diyab.net/selinux). I
haven't had time to update any of it in a while but it generally just
requires checking the newer patches and rebuilding the tgz from the
slackbuild script.
I included PAM because I think it has good advantages so all of the
packages I built include PAM support. Not sure what would be involved
in building without PAM. Most likely it just requires removing the
configure flags to enable PAM from the build scripts.
I'll be more than happy to help you out if you want.
Timothy,
Stephen Smalley wrote:
> On Thu, 2005-09-22 at 02:25 -0500, Lee Lowder wrote:
>
>>I am using Slackware 10.2 with kernel 2.6.13.2, and am wanting to get
>>going with SELinux. I know that Timothy Wood had made some packages in
>>the past, but his site (as listed on the SELinux for Distrubtions page)
>>gives a 403 error.
>
>
> Yes, looks like the old URL is dead. But looking at his top-level site
> (which redirects to his blog now), I see a reference to
> ftp://ftp.diyab.net/selinux/ as the new location for his Slackware
> selinux packages. Looks a little dated (based off the 9 March 2005
> release of SELinux).
>
>
>>I don't mind installing it all myself, but I am not sure where to start.
>> I do know I will need PAM, as Slackware does not include it by default.
>
>
> SELinux doesn't strictly require the use of PAM; you can port it to
> Slackware without necessarily converting to PAM. Using SELinux without
> PAM (and pam_selinux) just requires policy modifications to allow direct
> program reading of /etc/shadow and direct patching of login.
> pam_selinux was actually introduced by Red Hat when they integrated
> SELinux into Fedora Core; prior to that, login was directly patched for
> SELinux. So an alternative path is to resurrect the old login patch for
> SELinux and adjust policy accordingly.
>
>
>>If someone could point me to some info to help guide me through this, or
>>provide such info, I would greatly appreciate it. Thank you.
>
>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFDMvG1SYq2KfPEK/gRAmhZAJwL2uR8LksFu8GvUPm7Xm11N5itqgCfZ1Lc
MI5lEc0AbeHraiwh7BB+hFM=
=2pzw
-----END PGP SIGNATURE-----
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2005-09-22 18:02 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-09-22 7:25 Getting started with SELinux and Slackware Lee Lowder
2005-09-22 9:34 ` Russell Coker
2005-09-22 16:19 ` Lee Lowder
2005-09-22 21:22 ` Lyle Sigurdson
2005-09-22 22:23 ` Timothy
2005-09-23 17:03 ` Stephen Smalley
2005-09-22 12:28 ` Stephen Smalley
2005-09-22 18:02 ` Timothy [this message]
-- strict thread matches above, loose matches on Subject: below --
2007-12-20 13:40 Martin J. Green
2007-12-20 14:48 ` Stephen Smalley
[not found] <77FD49B9B8D2394FB1B63A63934913126A55770EA8@exchange.home.martinjgreen.me.uk>
2008-03-11 3:27 ` Martin J. Green
2008-03-11 8:22 ` Martin J. Green
2008-03-11 15:24 ` Stephen Smalley
[not found] ` <54EE10FFA0116B408D3A5172CB52729F01311A12DABF@exchange.home.martinjgreen.me.uk>
[not found] ` <1205260397.23866.175.camel@moss-spartans.epoch.ncsc.mil>
2008-03-11 20:35 ` Martin J. Green
2008-03-12 12:46 ` Stephen Smalley
2008-03-11 15:33 ` Stephen Smalley
2008-03-12 0:58 ` Russell Coker
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4332F1B5.2010704@diyab.net \
--to=timothy@diyab.net \
--cc=friedbob@sbcglobal.net \
--cc=sds@tycho.nsa.gov \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.