
SELinux has achieved its goal of protecting Linux systems from intrusion by unauthorized access. But the effort remains in the early adopter stage, and its supporters need to work on broader implementation and greater ease of use, according to Doc Shankar, an IBM distinguished engineer.
In <A HREF="http://searchenterpriselinux.techtarget.com/news/article/0,289142,sid39_gci1323731,00.html?track=sy184">a preview of his LinuxWorld Conference & Expo workshop,</A> Shankar said that the biggest benefit of SELinux is that systemwide policies automatically and absolutely enforce access controls. No one gets the unrestricted access of a "root" superuser; instead, each user is confined to what he needs to know, he said. In the case of a breech, an intruder is boxed in and can destroy only a portion of the system, he said.