Re: Selinux always disabled at boot from encrypted root fs

Mike Mohr <[email protected]> Fri, 2 Oct 2009 20:39:18 -0700
Newsgroups gmane.linux.cryptography
Message-ID <[email protected]>
Try grsecurity oh the "high" setting.  Grsecurity is, in my
experience, far superior to either Novell AppArmor or selinux.  Even
on the "high" setting I only had to tweak Firefox, Java, and Wine with
paxctl -- everything else works exactly as it should.  I've used it
successfully with loop-aes on Gentoo (which is sort of unversioned,
but at least since 2008.0), Fedora (8-11), and Ubuntu (8.04->9.04).

Just my .02.

-Mike

On Fri, Oct 2, 2009 at 7:51 PM, Fred Gazerblezeebe
<[email protected]> wrote:
> My system is up and running with an encrypted root partition and
> behaving exactly as it did pre-encryption except that selinux always
> comes up disabled at boot. Even passing the 'selinux=3D1' kernel paramete=
r
> is ineffective. =A0Once booted, selinux can be started with 'load_policy
> -i', after which it seems to behave normally, so it appears to be
> configured correctly, as it was before the root fs was encrypted.
>
> System info:
> intel core2duo cpu
> Fedora 11
> 2.6.31-rc5-git5 from kernel.org
> loop-AES-3.2g (compiled as module)
> aespipe-v2.3e
> util-linux-ng-2.15.1
>
> build-initrd.sh configuration:
> =A0 =A0 =A0* USEPIVOT=3D2
> =A0 =A0 =A0* BOOTDEV=3D/dev/sda1
> =A0 =A0 =A0* BOOTTYPE=3Dext3
> =A0 =A0 =A0* CRYPTROOT=3D/dev/sda2
> =A0 =A0 =A0* ROOTTYPE=3Dext4
> =A0 =A0 =A0* CIPHERTYPE=3DAES128
> =A0 =A0 =A0* GPGKEYFILE=3Drootkey.gpg
> =A0 =A0 =A0* SOURCEROOT=3D/
> =A0 =A0 =A0* DESTINATIONROOT=3D/mnt/build
> =A0 =A0 =A0* DESTINATIONPREFIX=3Dboot
> =A0 =A0 =A0* UTF8KEYBMODE=3D1
> =A0 =A0 =A0* LOADNATIONALKEYB=3D1
> =A0 =A0 =A0* USEGPGKEY=3D1
>
> My reading seems to point to this being an initrd issue as opposed to a
> loop-aes issue. However, in my experiments with dracut, TuxOnIce,
> building initrds from scratch, etc., I have been unable to get anything
> to work that is as small and efficient as the initrds produced by Jari's
> build-initrd.sh script, hence my post here.
>
> So my question is, must I live with this behavior or is it something
> that has already been solved? If it has been solved, would someone be so
> kind as to point me in the right direction; ideally at an
> appropriately-modified build-initrd.sh, but suggestions as to what I
> might try next would also be appreciated.
>
> Thanks.
>
> FG
>
>
>
>
>
>
> -
> Linux-crypto: =A0cryptography in and on the Linux system
> Archive: =A0 =A0 =A0 http://mail.nl.linux.org/linux-crypto/
>
>

-
Linux-crypto:  cryptography in and on the Linux system
Archive:       http://mail.nl.linux.org/linux-crypto/