Re: Let's enable AppArmor by default (why not?)

2017-10-26 Thread Neal Gompa
On Thu, Oct 26, 2017 at 1:49 PM, intrigeri wrote: > Hi Neal & others, > > Neal Gompa: >> I was recently pointed to the thread going on debian-devel about >> enabling AppArmor LSM in Debian, and as I read through your proposal, >> I felt it should be warranted to po

Re: Let's enable AppArmor by default (why not?)

2017-10-06 Thread Neal Gompa
unfortunate thing is that more comprehensive security models do lead to more complexity. > Now, if for some reason the project prefers to ship with SELinux > enforced instead of AppArmor, fine by me: I would strongly prefer this > option to nothing at all. I personally would like to see Debian ship SELinux by default, but as I'm not a part of Debian, my opinion doesn't matter. ;) But I definitely don't want people to think that SELinux is some crazy mountainous path full of terrible unknowns. If you have any other questions or would like to know more, feel free to ask, and I'll do my best to answer. :) Best regards, -- Neal Gompa (FAS: ngompa)