Systems: RHEL; SELinux/enforcing; cfengine-community 3.12
We have a stable, long-established set-up, which is now mostly RHEL7; a few thousand machines and VMs. Our CFE is 3.12. We happily run SELinux/enforcing.
I'm preparing our RHEL8 pathway. But this is throwing many SELinux errors. This is unexpected, as I would have thought (imagined, presumed, etc.) that the CFE RPM would already include the relevant SELinux info. (I'm guessing that RHEL8 is interposing more checks. But on the other hand, because CFE-3.12 knows about RHEL8, I would have thought that this would be already 'in the mix'.)
While I've been able to prepare some CFEngine/SELinux '.pp' files, this doesn't feel the right way to go.
Am I missing something?
We are not yet in a position to go higher than 3.12; nor are we yet using MPF. Both of those are on our team's roadmap, but currently independent from RHEL8. If you believe that these will basically fix the issues, then it would be very useful to know, as that will encourage us to restructure our roadmap to include this dependency chain.
Thanks.
-- David Lee
-- Diamond Light Source, UK