From mboxrd@z Thu Jan 1 00:00:00 1970 Message-ID: <553A60D2.30105@tycho.nsa.gov> Date: Fri, 24 Apr 2015 11:27:14 -0400 From: Stephen Smalley MIME-Version: 1.0 To: "Spector, Aaron" , "SELinux (selinux@tycho.nsa.gov)" , "Paul Moore (paul@paul-moore.com)" Subject: Re: Switching to enforcing mode introduces new policy issues? References: <363d72e72db54ed2a93f39f76d1811fd@MIVEXUSR1N01.corpzone.internalzone.com> <553A362B.7040500@tycho.nsa.gov> <0787916bff754fec87b219654e47b1e0@MIVEXUSR1N01.corpzone.internalzone.com> In-Reply-To: <0787916bff754fec87b219654e47b1e0@MIVEXUSR1N01.corpzone.internalzone.com> Content-Type: text/plain; charset=windows-1252 List-Id: "Security-Enhanced Linux \(SELinux\) mailing list" List-Post: List-Help: On 04/24/2015 11:18 AM, Spector, Aaron wrote: > I noticed the ratelimiting happening a while ago, but if it was happening here, I should get suppression logs correct? I've been checking my avc audits by examining dmesg / viewing that output via a serial console and nothing in there implies that I'm missing logs. When in permissive I can see the policy load audit (