<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: SE Linux Play Machine and Passwords</title>
	<atom:link href="http://etbe.coker.com.au/2008/04/02/se-linux-play-machine-passwords/feed/" rel="self" type="application/rss+xml" />
	<link>http://etbe.coker.com.au/2008/04/02/se-linux-play-machine-passwords/</link>
	<description>Linux, politics, and other interesting things</description>
	<pubDate>Sat, 11 Oct 2008 01:56:13 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
		<item>
		<title>By: Pavel</title>
		<link>http://etbe.coker.com.au/2008/04/02/se-linux-play-machine-passwords/#comment-13140</link>
		<dc:creator>Pavel</dc:creator>
		<pubDate>Tue, 22 Apr 2008 04:35:54 +0000</pubDate>
		<guid isPermaLink="false">http://etbe.coker.com.au/?p=553#comment-13140</guid>
		<description>Russell, 
A more generic Debian safety/security question, especially after you've mentioned incident with "restorecon":

Is in Debian any way of keeping records of all local per machine customisations of security policies (SELinux or other like regular file permissions), regulary verifying them and fixing/sending reports when found different?

For instance, I have a some limited rights (made via file group permissions) on my general-purpose-machine for all kind of active browser content (flash etc), but they are gone every time I'm updating the software.

Would it be right to configure SELinux for it or it is still better to make a virtual machine with all browsers?

Thanks, Pavel.</description>
		<content:encoded><![CDATA[<p>Russell,<br />
A more generic Debian safety/security question, especially after you&#8217;ve mentioned incident with &#8220;restorecon&#8221;:</p>
<p>Is in Debian any way of keeping records of all local per machine customisations of security policies (SELinux or other like regular file permissions), regulary verifying them and fixing/sending reports when found different?</p>
<p>For instance, I have a some limited rights (made via file group permissions) on my general-purpose-machine for all kind of active browser content (flash etc), but they are gone every time I&#8217;m updating the software.</p>
<p>Would it be right to configure SELinux for it or it is still better to make a virtual machine with all browsers?</p>
<p>Thanks, Pavel.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: etbe</title>
		<link>http://etbe.coker.com.au/2008/04/02/se-linux-play-machine-passwords/#comment-12774</link>
		<dc:creator>etbe</dc:creator>
		<pubDate>Wed, 02 Apr 2008 09:29:38 +0000</pubDate>
		<guid isPermaLink="false">http://etbe.coker.com.au/?p=553#comment-12774</guid>
		<description>Daniel: Strange, there is no reason why it shouldn't have worked.  At the minimum you prevented me from doing a password based login to my own account which counts as breaking the security goals of the box.

Thanks for the comment on this blog post and the comment in the thanks.txt file.

In future I would appreciate it if you could send me your email address in a suitable location (such as thanks.txt) so we could discuss them before I write a post about them.  Or of course an email would do (my address is well publicised).</description>
		<content:encoded><![CDATA[<p>Daniel: Strange, there is no reason why it shouldn&#8217;t have worked.  At the minimum you prevented me from doing a password based login to my own account which counts as breaking the security goals of the box.</p>
<p>Thanks for the comment on this blog post and the comment in the thanks.txt file.</p>
<p>In future I would appreciate it if you could send me your email address in a suitable location (such as thanks.txt) so we could discuss them before I write a post about them.  Or of course an email would do (my address is well publicised).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://etbe.coker.com.au/2008/04/02/se-linux-play-machine-passwords/#comment-12769</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Wed, 02 Apr 2008 07:13:09 +0000</pubDate>
		<guid isPermaLink="false">http://etbe.coker.com.au/?p=553#comment-12769</guid>
		<description>that's me, actually.
after i changed the password, i have tried to login with your account. but it didn't work.

either i have entered a bad password, or you have other security measure in place.</description>
		<content:encoded><![CDATA[<p>that&#8217;s me, actually.<br />
after i changed the password, i have tried to login with your account. but it didn&#8217;t work.</p>
<p>either i have entered a bad password, or you have other security measure in place.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
