Re: Sanity Check on Audit

Harry Hoffman <[email protected]> Thu, 06 Feb 2014 12:37:34 -0500
Newsgroups gmane.linux.redhat.general
Message-ID <[email protected]>
Mark,

That's not quite accurate. SELinux controls can be enabled to neuter
root's power.

Cheers,
Harry


On 02/06/2014 10:12 AM, [email protected] wrote:
> [email protected] wrote:
>> Paul,
>>
>> For "Anyone" it wouldn't be a problem, but a root user is allowed to do
>> anything.
>>
>> So a root is always be able to stop a process on the system.
>>
>> Think of a solution to lock ssh access (sshd_config) for everyone, but
>> you.
>>
>> And even this is no 100% solution.
>>
> And two cents from someone who's really isn't deeply into selinx: a root
> user could always
> $ echo 0 >/selinux/enforce
> and then, with selinux in permissive mode, could do anything root could
> normally do (i.e., anything).
> 
>        mark
> 

-- 
redhat-list mailing list
unsubscribe mailto:[email protected]?subject=unsubscribe
https://www.redhat.com/mailman/listinfo/redhat-list