▲ 243 ▼ What distros have you tried and thought, "Nope, this one's not for me"? (feddit.uk) submitted 2 years ago by case_when@feddit.uk to c/linux@lemmy.ml 379 comments fedilink hide all child comments I've been using Linux Mint since forever. I've never felt a reason to change. But I'm interested in what persuaded others to move.
[–] WalnutLum@lemmy.ml 5 points 2 years ago (1 child) RHEL, SELinux sucks and I hate it. permalink fedilink source hideshow 2 child comments replies: [–] mholiv@lemmy.world 8 points 2 years ago (1 child) I get it. It does have a learning curve. This being said, I would argue that without selinux Linux can’t really be meaningfully secure. It’s worth learning. Seljnux exits elsewhere too. I deploy Debian with selinux and it works well there as well. permalink fedilink source parent hideshow 2 child comments replies: [–] bhamlin@lemmy.world 3 points 2 years ago (2 children) The problem with SELinux is that everyone rushed to push it out, alongside packages affected by it without support for it. So it was a crapshoot whether or not you'd have something working each time. That is better now, but was initially a colossal pain in the ass for about five years or so. permalink fedilink source parent hideshow 4 child comments replies: [–] boblin@infosec.pub 2 points 2 years ago (1 child) What put me off selinux is that the officially documented way of generating a new policy is to run a service unconfined, and then generating the policy from its behaviour. This is backwards on so many levels... In contrast policy-based admission control in kubernetes is a delight to use, and creating new policies is actually doable outside of a lab. permalink fedilink source parent hideshow 2 child comments replies: [–] mholiv@lemmy.world 1 point 2 years ago You could preemptively write the policy if you know the context and policies you want to apply. I just don’t think it’s worth the time when you can generate a policy with two commands. permalink fedilink source parent [–] mholiv@lemmy.world 1 point 2 years ago Fair. But audit2allow makes it really easy to add support for apps without policies. For custom in-house apps I use this to spit out some nice policies that can be rolled out. permalink fedilink source parent
[–] mholiv@lemmy.world 8 points 2 years ago (1 child) I get it. It does have a learning curve. This being said, I would argue that without selinux Linux can’t really be meaningfully secure. It’s worth learning. Seljnux exits elsewhere too. I deploy Debian with selinux and it works well there as well. permalink fedilink source parent hideshow 2 child comments replies: [–] bhamlin@lemmy.world 3 points 2 years ago (2 children) The problem with SELinux is that everyone rushed to push it out, alongside packages affected by it without support for it. So it was a crapshoot whether or not you'd have something working each time. That is better now, but was initially a colossal pain in the ass for about five years or so. permalink fedilink source parent hideshow 4 child comments replies: [–] boblin@infosec.pub 2 points 2 years ago (1 child) What put me off selinux is that the officially documented way of generating a new policy is to run a service unconfined, and then generating the policy from its behaviour. This is backwards on so many levels... In contrast policy-based admission control in kubernetes is a delight to use, and creating new policies is actually doable outside of a lab. permalink fedilink source parent hideshow 2 child comments replies: [–] mholiv@lemmy.world 1 point 2 years ago You could preemptively write the policy if you know the context and policies you want to apply. I just don’t think it’s worth the time when you can generate a policy with two commands. permalink fedilink source parent [–] mholiv@lemmy.world 1 point 2 years ago Fair. But audit2allow makes it really easy to add support for apps without policies. For custom in-house apps I use this to spit out some nice policies that can be rolled out. permalink fedilink source parent
[–] bhamlin@lemmy.world 3 points 2 years ago (2 children) The problem with SELinux is that everyone rushed to push it out, alongside packages affected by it without support for it. So it was a crapshoot whether or not you'd have something working each time. That is better now, but was initially a colossal pain in the ass for about five years or so. permalink fedilink source parent hideshow 4 child comments replies: [–] boblin@infosec.pub 2 points 2 years ago (1 child) What put me off selinux is that the officially documented way of generating a new policy is to run a service unconfined, and then generating the policy from its behaviour. This is backwards on so many levels... In contrast policy-based admission control in kubernetes is a delight to use, and creating new policies is actually doable outside of a lab. permalink fedilink source parent hideshow 2 child comments replies: [–] mholiv@lemmy.world 1 point 2 years ago You could preemptively write the policy if you know the context and policies you want to apply. I just don’t think it’s worth the time when you can generate a policy with two commands. permalink fedilink source parent [–] mholiv@lemmy.world 1 point 2 years ago Fair. But audit2allow makes it really easy to add support for apps without policies. For custom in-house apps I use this to spit out some nice policies that can be rolled out. permalink fedilink source parent
[–] boblin@infosec.pub 2 points 2 years ago (1 child) What put me off selinux is that the officially documented way of generating a new policy is to run a service unconfined, and then generating the policy from its behaviour. This is backwards on so many levels... In contrast policy-based admission control in kubernetes is a delight to use, and creating new policies is actually doable outside of a lab. permalink fedilink source parent hideshow 2 child comments replies: [–] mholiv@lemmy.world 1 point 2 years ago You could preemptively write the policy if you know the context and policies you want to apply. I just don’t think it’s worth the time when you can generate a policy with two commands. permalink fedilink source parent
[–] mholiv@lemmy.world 1 point 2 years ago You could preemptively write the policy if you know the context and policies you want to apply. I just don’t think it’s worth the time when you can generate a policy with two commands. permalink fedilink source parent
[–] mholiv@lemmy.world 1 point 2 years ago Fair. But audit2allow makes it really easy to add support for apps without policies. For custom in-house apps I use this to spit out some nice policies that can be rolled out. permalink fedilink source parent