33 years in Linux, 30+ professionally, Unix+Linux security background in a past life at a fucking distro.
When I first install a new distro version, I do something very simple; maybe I configure a simple web page, for instance.
Usually the web server refuses to start, or something equally “so dumb it should have been seen in early testing and doesn’t even get to the challenge I set before it” stupid. If the distro can’t test something so basic, then I know they’re not prepared to consider selinux implications while maintaining or debugging the distro. I don’t need to blaze a trail the distro can’t be arsed to.
Then I mod away the config in my template and hope the distro can pull out their proverbial head in 5 years.
Absolutely this.
33 years in Linux, 30+ professionally, Unix+Linux security background in a past life at a fucking distro.
When I first install a new distro version, I do something very simple; maybe I configure a simple web page, for instance.
Usually the web server refuses to start, or something equally “so dumb it should have been seen in early testing and doesn’t even get to the challenge I set before it” stupid. If the distro can’t test something so basic, then I know they’re not prepared to consider selinux implications while maintaining or debugging the distro. I don’t need to blaze a trail the distro can’t be arsed to.
Then I mod away the config in my template and hope the distro can pull out their proverbial head in 5 years.
The easiest path needs to be the safest path