[DECOMMISSIONED] Red Hat Security Blog: April 2014 archives
-
New Red Hat Enterprise Linux 7 Security Feature: systemd Starting Daemons
Why is this a security feature? In previous releases of Red Hat Enterprise Linux, system daemons would be started in one of two ways: At boot, init (sysV) launches an initrc script and then this script launches the daemon. An admin can log in and launch the init script by hand, causing the daemon to run. Let me show you what this means from an SELinux point of view. NOTE: In the code below, @ means execute, --> indicates transition, and === indicates a client/server communication. The...
