Re: [Discuss] SELinux & IPTables

2014-04-02 Thread John Malloy
That's a good idea! On Wed, Apr 2, 2014 at 11:21 PM, Peter (peabo) Olson wrote: > On April 2, 2014 at 2:28 PM Jerry Feldman wrote: > > One issue is that sometimes, companies make this a requirement, and the > > IT people who do the real work just have to follow the rules. > > Whenever I set u

Re: [Discuss] SELinux & IPTables

2014-04-02 Thread Peter (peabo) Olson
On April 2, 2014 at 2:28 PM Jerry Feldman wrote: > One issue is that sometimes, companies make this a requirement, and the > IT people who do the real work just have to follow the rules. > Whenever I set up a new system I always to to /etc/selinux and change > config to SELINUX=disabled > I recent

Re: [Discuss] Unsubscribe

2014-04-02 Thread Kevin D. Clark
Michael Webb writes: > Unsubscribe Heres how to unsubscribe: First, ask your Internet Provider to mail you an Unsubscribing Kit. Then follow these directions. The kit will most likely be the standard no-fault type. Depending on requirements, System A and/or System B can be used. When operating

Re: [Discuss] easy clustering of applications

2014-04-02 Thread Richard Pieri
Bill Bogstad wrote: An application that does little IO, has a high memory footprint, and modifies all of it between IO requests would make for very expensive checkpointing. Every checkpoint could require transferring multiple gigabytes of modified RAM. A CPU can dirty RAM way faster then a

Re: [Discuss] SELinux & IPTables

2014-04-02 Thread Jerry Feldman
One issue is that sometimes, companies make this a requirement, and the IT people who do the real work just have to follow the rules. Whenever I set up a new system I always to to /etc/selinux and change config to SELINUX=disabled I recently change SELINUXTYPE to disabled, and screwed up everything

Re: [Discuss] easy clustering of applications

2014-04-02 Thread Bill Bogstad
On Wed, Apr 2, 2014 at 7:02 AM, Edward Ned Harvey (blu) wrote: >> From: discuss-bounces+blu=nedharvey@blu.org [mailto:discuss- >> bounces+blu=nedharvey@blu.org] On Behalf Of Tom Metro >> >> Edward Ned Harvey (blu) wrote: >> >>Tom Metro wrote: >> >> It does seem like every application has i

Re: [Discuss] SELinux & IPTables

2014-04-02 Thread Richard Pieri
Greg Rundlett (freephile) wrote: It's rather (annoyingly) humorous that there is a webpage at the NSA titled "Current State of SELinux" http://www.nsa.gov/research/_files/selinux/papers/x/text8.shtml which is a blank white page. That's funny. Regardless, my suggestion not to use SELinux has no

Re: [Discuss] SELinux & IPTables

2014-04-02 Thread Greg Rundlett (freephile)
It's rather (annoyingly) humorous that there is a webpage at the NSA titled "Current State of SELinux" http://www.nsa.gov/research/_files/selinux/papers/x/text8.shtml which is a blank white page. The page in question is supposed to be a slide in a presentation, and can be seen here: http://www.nsa

Re: [Discuss] Unsubscribe

2014-04-02 Thread Daniel Barrett
On 04/01/2014 10:21 PM, ma...@mohawksoft.com wrote: > Just because someone says something doesn't mean its true. Ah, but sometimes it does. The phenomenon is called a performative utterance. http://en.wikipedia.org/wiki/Performative_utterance When someone says, "I now pronounce you husband and

Re: [Discuss] SELinux & IPTables

2014-04-02 Thread Richard Pieri
John Malloy wrote: Does anyone have any suggestions for Best Practices in configuring SELinux & IPTables for a RedHat (RHEL6) server running Apache, PHP, and connecting to an Oracle DB (using OCI8)? Don't use SELinux unless you're required to use it. For example, US government contracts. If y

Re: [Discuss] SELinux & IPTables

2014-04-02 Thread Greg Rundlett (freephile)
I wrote up a short response on my wiki https://freephile.org/wiki/index.php/Troubleshooting_selinux Greg Rundlett http://eQuality-Tech.com http://freephile.org On Wed, Apr 2, 2014 at 10:38 AM, John Malloy wrote: > Does anyone have any suggestions for Best Practices in configuring SELinux > & I

Re: [Discuss] SELinux & IPTables

2014-04-02 Thread markw
My first rule of thumb is to not use IPTables until after everything is setup and running. Then start it and fix what breaks. My second rule of thumb is to not enable SELinux until after everything is setup and running. Then enable it and fix what breaks. You really really need a working base lin

[Discuss] SELinux & IPTables

2014-04-02 Thread John Malloy
Does anyone have any suggestions for Best Practices in configuring SELinux & IPTables for a RedHat (RHEL6) server running Apache, PHP, and connecting to an Oracle DB (using OCI8)? Thanks! -- John Malloy jomal...@gmail.com ___ Discuss mailing list Di

Re: [Discuss] Unsubscribe

2014-04-02 Thread Kent Borg
On 04/01/2014 10:21 PM, ma...@mohawksoft.com wrote: Just because someone says something doesn't mean its true. It reminds me of a Shakespeare line, from Henry IV. I like to ham it up, and with great bravado and gravitas, proclaim (as Glendower): I can call spirits from the vasty deep. And

Re: [Discuss] easy clustering of applications

2014-04-02 Thread Edward Ned Harvey (blu)
> From: discuss-bounces+blu=nedharvey@blu.org [mailto:discuss- > bounces+blu=nedharvey@blu.org] On Behalf Of Tom Metro > > Edward Ned Harvey (blu) wrote: > >>Tom Metro wrote: > >> It does seem like every application has its own unique approach to > >> clustering. There is no generalized so