[DSE-Dev] CONFIG_SECURITY_SELINUX_CHECKREQPROT_VALUE

Laurent Bigonville bigon at debian.org
Tue Apr 11 15:12:55 UTC 2017


Le 11/04/17 à 16:53, Christian Göttsche a écrit :
> I am using the boot flag *checkreqprot=0* without any complications or
> policy changes.
>
> @Laurent
> if you are willing, one could alter the selinux-activate script to set
> the boot flag

I think it's too late now to do that (and I don't know all the 
implications).

I prefer that this is changed in the kernel itself TBH

>
> @Ben
>> Maybe we'll go with the new default for buster.
> if there are no objections from the Debian SELinux team or users, please do so




More information about the SELinux-devel mailing list