My advice on SELinux container labeling | Red Hat Developer https://developers.redhat.com/articles/2025/04/11/my-advice-selinux-container-labeling?sc_cid=RHCTG0250000446542 #containers #podman #docker #selinux
My advice on SELinux container labeling | Red Hat Developer https://developers.redhat.com/articles/2025/04/11/my-advice-selinux-container-labeling?sc_cid=RHCTG0250000446542 #containers #podman #docker #selinux
Archivierung und Kompression mit tar: Grundlagen, Optionen und Beispiele
tar (Tape Archiver) ist das Standard-Archivierungswerkzeug unter Linux, das mehrere Dateien und Ordner zu einem einzigen Archiv bündelt. Im Gegensatz zu gzip, bzip2 und xz komprimiert tar nicht selbst, sondern arbeitet mit Kompressionstools zusammen (z, j, J). Es erhält vollständige Metadaten inklusive Berechtigungen und SELinux-Kontexte. Wichtige Optionen von tar -c (create) : Erstellt ein neues Archiv. -f (file name). : Gibt den Dateinamen des Archivs an. # Einen Ordner […]https://andreas-moor.de/archivierung-und-kompression-mit-tar-grundlagen-optionen-und-beispiele/
Vergleich von Archivierung und Kompression unter Linux: tar/star, gzip, bzip2, xz und zip
Archivierungs- und Kompressionstechniken sind wichtige Werkzeuge, um Dateien und Verzeichnisse unter Linux effizient zu speichern. Dabei unterscheidet man zwischen der Archivierung, bei der mehrere Dateien zu einer Einheit gebündelt werden, und der Kompression, bei der die Datenmenge verkleinert wird. Archivierung und Kompression: tar als Pflicht für Ordner tar ist das Standardwerkzeug für die Archivierung von Ordnern unter Linux. Es bündelt Dateien und Verzeichnisse in einem Archiv, […]Highlights from the LSM, SELinux, and audit pull requests that have been merged for Linux v6.19.
https://paul-moore.com/blog/d/2025/12/linux_v619_merge_window.html
[Перевод] SELinux: интеграция с Zabbix и другими инструментами
Всем привет! Мы делаем проекты по Zabbix, накопили большую экспертизу и решили сделать переводы нескольких статей, которые нам показались интересными и полезными. Наверняка, будут полезны и вам. Также своим опытом делимся в телеграм-канале zabbix_ru , где вы можете найти полезные материалы и записи наших вебинаров, опубликованных на нашем ютуб-канале (прим. переводчика). Миграция с MySQL на PostgreSQL — первая статья цикла переводов. В этой статье подробно рассмотрены основы SELinux, его правильная интеграция с Zabbix и способы эффективного создания собственных политик SELinux для решения распространённых проблем. Также показано, как контролировать SELinux непосредственно в Zabbix, что поможет повысить безопасность системы и упростить повседневное администрирование. Данное руководство предназначено для дистрибутивов на основе RPM (RHEL, CentOS, Rocky Linux, AlmaLinux, Fedora, …).
The world needs a #luks2 enrypted, #immutable #atomic #linux whith #selinux, #flatpaks and the #COSMICdesktop to attack Microsoft. Right now, would be perfect :owi: #aerynos #fedora #opensuse
AlmaLinux 9.7 chega com melhorias de desempenho e segurança reforçada
🔗 https://tugatech.com.pt/t74445-almalinux-9-7-chega-com-melhorias-de-desempenho-e-seguranca-reforcada
i get a bit annoyed at #linux commenters who look at #wayland's efforts to isolate app windows from each other and go "this is pointless, because all apps run as the same user anyway and a malicious/exploited app can therefore still steal all the data it wants"
like, yes, but we also have things like #apparmor and #selinux to prevent apps from doing what they shouldn't in case of being hacked
and #flatpak can isolate its apps even further
there is no one perfect app security solution, and on a desktop computer, where the end user is in charge (unlike smartphones and tablets), there will never be, but there are still improvements being made
Alerta: Molduras digitais Uhale com Android estão a descarregar malware ao iniciar
🔗 https://tugatech.com.pt/t74274-alerta-molduras-digitais-uhale-com-android-estao-a-descarregar-malware-ao-iniciar
#AES #amazon #android #apple #base #botnet #chave #criptografia #cve #dex #google #grave #malware #marcas #riscos #root #segurança #SELinux #sem #servidor #vulnerabilidades
@woodstock In total Debian + some Ubuntu environment, that is why not thinking much about using #SELinux :)
Seriously, #SELinux. I think that on most Linux desktops and even home servers, it's complete security theater and needs to be taken out behind the shed and disabled by default.
Ridiculous.
Did users actually ask for this? I guarantee you they did not.
I set up #garage as an S3 endpoint locally so I can have the same backup target mode in my internal network.
Let's just say that, at least with the default settings, that's not friendly to a USB HDD.
I replaced it with a CIFS share which was flawless and much faster.
Except for the fuckery that is #SELinux that I had to figure out before the export could actually be written to.
But you know what? I can't be arsed. That's an #ansible task that a LLM spits out before I've read the manpage.
Leap 16 kicks off a new era for #openSUSE. #2038-safe, #SELinux by default, improved migration tools, and parallel package downloads. Read the full announcement: https://news.opensuse.org/2025/10/01/next-chapter-opens-with-leap-release/ #Linux #Endof10
openSUSE 16 walked into Fedora’s room like:
“Nice setup… mind if I copy it?” 😏
Fedora: Anaconda WebUI, Cockpit, SELinux, Ansible, Btrfs (no Snapper).
openSUSE: Agama Web Installer, Cockpit, SELinux, Snapper + Btrfs, Ansible.
Basically Fedora with an undo button.
Different wallpaper, same playbook.😆
#Fedora #openSUSE #Linux #Btrfs #Snapper #SELinux #Ansible #Cockpit #AgamaInstaller #YaST #SysadminHumor #LinuxHumor #FOSS #TechSarcasm #LinuxCommunity
SELinux: The Good, The Bad and The Worst ― Luca Fusè
https://video.linux.it/videos/watch/38a4e964-7d63-47ed-92ef-b9055f222c92
#SUSE #Linux Enterprise Server (SLES) 16 is out:
https://www.suse.com/news/suse-linux-enterprise-server-16-ai-ready-long-term-support/
See this blog post for a broad overview of what's new:
https://www.suse.com/c/what-is-new-in-suse-linux-enterprise-server-16-0/
Like #Cockpit as "Modern, Web-Based Server Management" tool, #Ansible integration, the transition to #SELinux, and #NetworkManager as the sole networking stack (replacing wicked).
The three genders
Finally upgraded to @opensuse Leap 16.0 - the https://github.com/openSUSE/opensuse-migration-tool by @lkocman worked like a charm.
openSUSE-2gb-fsn1-1:~ # cat /etc/os-release
NAME="openSUSE Leap"
VERSION="16.0"
SELinux is finally enabled and enforcing and after new policy forgejo-runner quadlet can talk to user podman socket again.