<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SELinux on Ubuntu (part 1)</title>
	<atom:link href="http://securityblog.org/brindle/2008/09/14/selinux-on-ubuntu-part-1/feed/" rel="self" type="application/rss+xml" />
	<link>http://securityblog.org/brindle/2008/09/14/selinux-on-ubuntu-part-1/</link>
	<description>The ramblings of security neophyte Joshua Brindle</description>
	<lastBuildDate>Wed, 30 Jun 2010 13:49:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: linux_user</title>
		<link>http://securityblog.org/brindle/2008/09/14/selinux-on-ubuntu-part-1/comment-page-1/#comment-49382</link>
		<dc:creator>linux_user</dc:creator>
		<pubDate>Thu, 07 Jan 2010 02:25:18 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.org/brindle/?p=28#comment-49382</guid>
		<description>Thanks for this. I too was baffled that everything was running as root:sysadm_r:sysadm_t, until I read the thing about upstart. Makes sense because the &quot;original&quot; SELinux ran on Redhat-like systems where sysvinit is the init program rather than upstart.</description>
		<content:encoded><![CDATA[<p>Thanks for this. I too was baffled that everything was running as root:sysadm_r:sysadm_t, until I read the thing about upstart. Makes sense because the &#8220;original&#8221; SELinux ran on Redhat-like systems where sysvinit is the init program rather than upstart.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Waqar Afridi</title>
		<link>http://securityblog.org/brindle/2008/09/14/selinux-on-ubuntu-part-1/comment-page-1/#comment-49354</link>
		<dc:creator>Waqar Afridi</dc:creator>
		<pubDate>Tue, 30 Jun 2009 10:46:08 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.org/brindle/?p=28#comment-49354</guid>
		<description>Here is the short-cut

try

sudo apt-get install selinux

or use synaptic manager and install selinux from there

It works.</description>
		<content:encoded><![CDATA[<p>Here is the short-cut</p>
<p>try</p>
<p>sudo apt-get install selinux</p>
<p>or use synaptic manager and install selinux from there</p>
<p>It works.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: m45</title>
		<link>http://securityblog.org/brindle/2008/09/14/selinux-on-ubuntu-part-1/comment-page-1/#comment-49350</link>
		<dc:creator>m45</dc:creator>
		<pubDate>Mon, 15 Jun 2009 10:53:21 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.org/brindle/?p=28#comment-49350</guid>
		<description>Awaiting part 2 :)</description>
		<content:encoded><![CDATA[<p>Awaiting part 2 <img src='http://securityblog.org/brindle/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff Schroeder</title>
		<link>http://securityblog.org/brindle/2008/09/14/selinux-on-ubuntu-part-1/comment-page-1/#comment-48533</link>
		<dc:creator>Jeff Schroeder</dc:creator>
		<pubDate>Tue, 16 Sep 2008 06:57:06 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.org/brindle/?p=28#comment-48533</guid>
		<description>@Josh:
Your changed policy is better than the existing one in ubuntu. Therefor, it should be the one that ships if at all possible.


Thats what it would be nice if you were to file a bug about.</description>
		<content:encoded><![CDATA[<p>@Josh:<br />
Your changed policy is better than the existing one in ubuntu. Therefor, it should be the one that ships if at all possible.</p>
<p>Thats what it would be nice if you were to file a bug about.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joshua Brindle</title>
		<link>http://securityblog.org/brindle/2008/09/14/selinux-on-ubuntu-part-1/comment-page-1/#comment-48478</link>
		<dc:creator>Joshua Brindle</dc:creator>
		<pubDate>Mon, 15 Sep 2008 13:19:28 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.org/brindle/?p=28#comment-48478</guid>
		<description>@Jeff

Well, the libraries are already updated (Manoj from Debian took that back over I guess, I hope he doesn&#039;t disappear again) and the refpolicy I&#039;m using is not the one you ship so I&#039;m not exactly sure what I&#039;d be filing bugs about.</description>
		<content:encoded><![CDATA[<p>@Jeff</p>
<p>Well, the libraries are already updated (Manoj from Debian took that back over I guess, I hope he doesn&#8217;t disappear again) and the refpolicy I&#8217;m using is not the one you ship so I&#8217;m not exactly sure what I&#8217;d be filing bugs about.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeff Schroeder</title>
		<link>http://securityblog.org/brindle/2008/09/14/selinux-on-ubuntu-part-1/comment-page-1/#comment-48476</link>
		<dc:creator>Jeff Schroeder</dc:creator>
		<pubDate>Mon, 15 Sep 2008 13:01:00 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.org/brindle/?p=28#comment-48476</guid>
		<description>Ubuntu&#039;s next release, code-named &quot;Intrepid Ibex&quot; is right around the corner. Can you file bugs and work to get your changes shipping in the next version of Ubuntu?

http://launchpad.net</description>
		<content:encoded><![CDATA[<p>Ubuntu&#8217;s next release, code-named &#8220;Intrepid Ibex&#8221; is right around the corner. Can you file bugs and work to get your changes shipping in the next version of Ubuntu?</p>
<p><a href="http://launchpad.net" rel="nofollow">http://launchpad.net</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin Orr</title>
		<link>http://securityblog.org/brindle/2008/09/14/selinux-on-ubuntu-part-1/comment-page-1/#comment-48470</link>
		<dc:creator>Martin Orr</dc:creator>
		<pubDate>Mon, 15 Sep 2008 11:57:41 +0000</pubDate>
		<guid isPermaLink="false">http://securityblog.org/brindle/?p=28#comment-48470</guid>
		<description>To build a Debian package:
sudo apt-get install build-essential fakeroot
sudo apt-get build-dep $pkg
apt-get source $pkg
cd $pkgdir
debian/rules build
fakeroot debian/rules binary

Creates .debs in the directory containing $pkgdir.

I maintain a quilt series of refpolicy patches for Debian at http://www.martinorr.name/selinux/patches.  In particular this includes all the patches in the Debian policy package.  They might be of some use to you (but not with upstart or tmpfs /var/run).  The aim is one day to get them submitted upstream.</description>
		<content:encoded><![CDATA[<p>To build a Debian package:<br />
sudo apt-get install build-essential fakeroot<br />
sudo apt-get build-dep $pkg<br />
apt-get source $pkg<br />
cd $pkgdir<br />
debian/rules build<br />
fakeroot debian/rules binary</p>
<p>Creates .debs in the directory containing $pkgdir.</p>
<p>I maintain a quilt series of refpolicy patches for Debian at <a href="http://www.martinorr.name/selinux/patches" rel="nofollow">http://www.martinorr.name/selinux/patches</a>.  In particular this includes all the patches in the Debian policy package.  They might be of some use to you (but not with upstart or tmpfs /var/run).  The aim is one day to get them submitted upstream.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
