Re: Selinux always disabled at boot from encrypted root fs
Mike Mohr <[email protected]> Fri, 2 Oct 2009 20:39:18 -0700
| Newsgroups | gmane.linux.cryptography |
|---|---|
| Message-ID | <[email protected]> |
Try grsecurity oh the "high" setting. Grsecurity is, in my experience, far superior to either Novell AppArmor or selinux. Even on the "high" setting I only had to tweak Firefox, Java, and Wine with paxctl -- everything else works exactly as it should. I've used it successfully with loop-aes on Gentoo (which is sort of unversioned, but at least since 2008.0), Fedora (8-11), and Ubuntu (8.04->9.04). Just my .02. -Mike On Fri, Oct 2, 2009 at 7:51 PM, Fred Gazerblezeebe <[email protected]> wrote: > My system is up and running with an encrypted root partition and > behaving exactly as it did pre-encryption except that selinux always > comes up disabled at boot. Even passing the 'selinux=3D1' kernel paramete= r > is ineffective. =A0Once booted, selinux can be started with 'load_policy > -i', after which it seems to behave normally, so it appears to be > configured correctly, as it was before the root fs was encrypted. > > System info: > intel core2duo cpu > Fedora 11 > 2.6.31-rc5-git5 from kernel.org > loop-AES-3.2g (compiled as module) > aespipe-v2.3e > util-linux-ng-2.15.1 > > build-initrd.sh configuration: > =A0 =A0 =A0* USEPIVOT=3D2 > =A0 =A0 =A0* BOOTDEV=3D/dev/sda1 > =A0 =A0 =A0* BOOTTYPE=3Dext3 > =A0 =A0 =A0* CRYPTROOT=3D/dev/sda2 > =A0 =A0 =A0* ROOTTYPE=3Dext4 > =A0 =A0 =A0* CIPHERTYPE=3DAES128 > =A0 =A0 =A0* GPGKEYFILE=3Drootkey.gpg > =A0 =A0 =A0* SOURCEROOT=3D/ > =A0 =A0 =A0* DESTINATIONROOT=3D/mnt/build > =A0 =A0 =A0* DESTINATIONPREFIX=3Dboot > =A0 =A0 =A0* UTF8KEYBMODE=3D1 > =A0 =A0 =A0* LOADNATIONALKEYB=3D1 > =A0 =A0 =A0* USEGPGKEY=3D1 > > My reading seems to point to this being an initrd issue as opposed to a > loop-aes issue. However, in my experiments with dracut, TuxOnIce, > building initrds from scratch, etc., I have been unable to get anything > to work that is as small and efficient as the initrds produced by Jari's > build-initrd.sh script, hence my post here. > > So my question is, must I live with this behavior or is it something > that has already been solved? If it has been solved, would someone be so > kind as to point me in the right direction; ideally at an > appropriately-modified build-initrd.sh, but suggestions as to what I > might try next would also be appreciated. > > Thanks. > > FG > > > > > > > - > Linux-crypto: =A0cryptography in and on the Linux system > Archive: =A0 =A0 =A0 http://mail.nl.linux.org/linux-crypto/ > > - Linux-crypto: cryptography in and on the Linux system Archive: http://mail.nl.linux.org/linux-crypto/