CyberSecurityClubMoscow / meetups

7 stars 0 forks source link

[MEETUP] SELinux #2

Closed mitilan closed 4 years ago

mitilan commented 4 years ago

SELinux architecture, demo.

mitilan commented 4 years ago

SELinux tutorial от Digital Ocean. Не зря поисковики ставят на первую строчку

https://www.digitalocean.com/community/tutorials/an-introduction-to-selinux-on-centos-7-part-1-basic-concepts

mitilan commented 4 years ago

Книга. Свен Вермейлен «Администрирование системы защиты SELinux»

Кроме этого от Свена же - репо с авторскими тулами для SELinux (и не только) https://github.com/sjvermeu/small.coding

mitilan commented 4 years ago

Nice cheat sheet

https://opensource.com/article/18/7/sysadmin-guide-selinux

mitilan commented 4 years ago

Официальный док от NSA "Configuring the SELinux Policy" https://www.nsa.gov/Portals/70/documents/resources/everyone/digital-media-center/publications/research-papers/configuring-selinux-policy-report.pdf

mitilan commented 4 years ago

Проект SELinux на GitHub

http://github.com/selinuxproject

И в частности репо SELinux Notebook - отличный сборник доков.

https://github.com/SELinuxProject/selinux-notebook/blob/main/src/toc.md

И в частности исходники политик:

https://github.com/SELinuxProject/refpolicy

mitilan commented 4 years ago

Linux Security Modules (LSM) - механизм подключения SELinux к ядру

https://www.kernel.org/doc/html/latest/admin-guide/LSM/index.html

mitilan commented 4 years ago

Just Stop Disabling SELinux http://stopdisablingselinux.com/

mitilan commented 4 years ago

SELinux Wiki from Gentoo - https://wiki.gentoo.org/wiki/SELinux

dok2d commented 4 years ago

В новом релизе ядра Linux ускорили работу SELinux

https://lore.kernel.org/lkml/CAHC9VhTX8gkUui6AiTJMJgcohXa=TOqdO==rEDk=Mquz9sCNKA@mail.gmail.com/ https://github.com/SELinuxProject/selinux-kernel/releases/tag/v5.8

https://www.phoronix.com/scan.php?page=news_item&px=Linux-5.8-SELinux-Optimizations