Skip to content

Facilitate use of secured Linux environments for application providers #8

@kayatate

Description

@kayatate

+LSB Specification Proposal
+
+Problem Statement:
+------------------
+
+It can be difficult for application providers to install their products on Linux
+systems that have security features turned on compared to those with the
+features turned off. Documentation is needed to guide application providers
+for how to build their applications and installers for systems with SELinux and

  • apparmor in use as well as for non-secured systems.
    +
    +(Proposed) Solution:
    +--------------------
    +
    +Create guideline documentation for applications for installing and running within
    +typical SELinux and apparmor environments compared to environments not using them.
    +
    +Solution Discussion Links:
    +--------------------------
    +
    +Solution Rationale:
    +------------------
    +
    +Many customers today want to use their preferred applications in a secure environment.
    +A number of commercial applications are programmed to use more system facilities
    +than are allowed to them in the secured environment. To complete the installation and
    +run successfully, they advise the customer to turn off the security feature. The
    +customer is then forced to make a decision between a more secure environment and
    +using the application. Clearer advice on how to set up applications in secured
    +environments would assist application providers in working within the environment.
    +
    +Distributions Support:
    +----------------------
    +
    +Ubuntu and OpenSUSE ship with apparmor turned on by default.
    +Fedora ships with SELinux turned on by default.
    +
    +Verification Test:
    +------------------
    +
    +Documentation, testing not required
    +

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions