Unfortunately, that rather depends on how much money is available to spend on a solution. (Unpleasant, but true.) I'm going to have difficulty persuading my manager that I should stop my tasks for a few weeks to learn and implement selinux on several Linux-based platforms. From his perspective, I will take some paid vacation from revenue-enhancing tasks in order to add a requirement for increased operational expenditure down the road.
From the perspective of somebody who has only dabbled, selinux is a bit like monitoring: there's a wide and deep ocean of domain knowledge behind a single word. I'd like to know more, but I don't have the time without neglecting my currently assigned tasks.
There's nothing about selinux on the puppet forge right now, but Google turns up any number of links. I liked these:
http://allmybase.com/2011/04/26/easily-managing-selinux-policies-with-puppet/
http://serverfault.com/questions/30796/reasons-to-disable-enable-selinux
But my liking something and my appreciating how it helps are not criteria that will help me implement something on production systems.
On Sat, Sep 01, 2012 at 10:33:43PM -0700, kegstand wrote:
> disabling selinux is never the solution
>
> On Sat, Sep 1, 2012 at 7:16 PM, purple grape <[1]
purple...@gmail.com>
> wrote:
>
> just disable selinux .
>
> --
> You received this message because you are subscribed to the Google
> Groups "Puppet Users" group.
> To post to this group, send email to [2]
puppet...@googlegroups.com.
> To unsubscribe from this group, send email to
> [3]
puppet-users...@googlegroups.com.
> For more options, visit this group at
> [4]
http://groups.google.com/group/puppet-users?hl=en.
> References
>
> Visible links
> 1. mailto:
purple...@gmail.com
> 2. mailto:
puppet...@googlegroups.com
> 3. mailto:
puppet-users%2Bunsu...@googlegroups.com
> 4.
http://groups.google.com/group/puppet-users?hl=en