Post #3454692
2026-06-28 18:14 UTC
@grono@mastodon.com.pl well, I'm bigger fan of AppArmor instead of SELinux.
Novell has done a great job, in fact, it pioneered practical implementations (e.g., changing the “hats” in mpm_prefork, etc.), which were subsequently adopted by Ubuntu and then merged into Debian. I would like to point out here that, for example, the Austrian Debian distribution Proxmox uses AppArmor for unprivileged containers (LXD and Incus as well).
Ultimately, when it comes to Linux-based MAC/RBAC, AppArmor is, in my humble opinion, better - it offers greater control, is simpler to implement, and the ability to dynamically change HATs and quickly extend profiles is more convenient for me.
As for OpenSUSE itself - I always see the same issue - whether to align more closely with Debian or Red Hat, and this is the source of disagreements over which standard to adopt.
Replies (1)
-
@grono@mastodon.com.pl 2026-06-28 20:37
@spoofy@mastodon.com.pl well put! Glad to hear I'm not the only one finding apparmor better. I think SELinux makes sense for something like Android where the user is not expected to step outside it's userspace world. Anyway I was sad to see SUSE changing the default...