Skip to content

Facilitate use of secured Linux environments for application providers #8

Description

@kayatate

+LSB Specification Proposal
+
+Problem Statement:
+------------------
+
+It can be difficult for application providers to install their products on Linux
+systems that have security features turned on compared to those with the
+features turned off. Documentation is needed to guide application providers
+for how to build their applications and installers for systems with SELinux and

  • apparmor in use as well as for non-secured systems.
    +
    +(Proposed) Solution:
    +--------------------
    +
    +Create guideline documentation for applications for installing and running within
    +typical SELinux and apparmor environments compared to environments not using them.
    +
    +Solution Discussion Links:
    +--------------------------
    +
    +Solution Rationale:
    +------------------
    +
    +Many customers today want to use their preferred applications in a secure environment.
    +A number of commercial applications are programmed to use more system facilities
    +than are allowed to them in the secured environment. To complete the installation and
    +run successfully, they advise the customer to turn off the security feature. The
    +customer is then forced to make a decision between a more secure environment and
    +using the application. Clearer advice on how to set up applications in secured
    +environments would assist application providers in working within the environment.
    +
    +Distributions Support:
    +----------------------
    +
    +Ubuntu and OpenSUSE ship with apparmor turned on by default.
    +Fedora ships with SELinux turned on by default.
    +
    +Verification Test:
    +------------------
    +
    +Documentation, testing not required
    +

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions