Uploaded image for project: 'Percona Server for MySQL'
  1. Percona Server for MySQL
  2. PS-7049

SELinux and AppArmor Policy Updates

Details

    • New Feature
    • Status: Done
    • Medium
    • Resolution: Fixed
    • 8.0.x
    • 8.0.23-14 (Q1 2021)
    • None

    Description

      What is it we are doing?

      We have SELinux profiles in our source tree, and much of this is already maintained upstream in MySQL CE, but we don't currently perform automated testing as part of QA to verify that these profiles work correctly with Percona Server.  We should develop the appropriate QA processes and begin maintenance of any changes required in the SELinux profiles as part of our patchset.

      Why are we doing it?

      SELinux is used by many large enterprises to assist in meeting security and compliance objectives.  It should be as simple a matter as installing our software normally for them to use SELinux with PS.

      Are there any restrictions on when this needs to be done?

      This should be resolved in 5.7 if possible, but must be resolved for 8.0 before launch.

      Are there any unanswered questions we have about this before it can be worked on?

      Do the current profiles work in enforcing mode?  Do we have any changes we need to make from upstream?  Should we rebase our packaging on upstream to gain the simplified installation of SELinux profiles?

       

      https://confluence.percona.com/display/PS/Certify+PS+for+SELinux+Support

      Attachments

        Issue Links

          Activity

            People

              kamil.holubicki Kamil Holubicki
              kathy.williamson Kathy Williamson (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 15 minutes
                  15m
                  Remaining:
                  Time Spent - 1 week, 2 days, 4 hours, 16 minutes Remaining Estimate - 15 minutes
                  15m
                  Logged:
                  Time Spent - 1 week, 2 days, 4 hours, 16 minutes Remaining Estimate - 15 minutes
                  1w 2d 4h 16m

                  Smart Checklist