I found Sven's cookbook a good first step for when you go beyond sys admin
and into policy writing:
https://www.packtpub.com/networking-and-servers/selinux-cookbook
Taking the time to understand how the referece policy is structured will
really help, as you will always be using its interfaces in your policies:
https://github.com/TresysTechnology/refpolicy/wiki
There's no real substitute for getting in there and confining your first
service though.
Cheers
Phil
From: Robin Lee Powell <rlpowell(a)digitalkingdom.org>
To: "Parker, Michael D." <Michael.D.Parker(a)ga.com>
Cc: "selinux(a)lists.fedoraproject.org"
<selinux(a)lists.fedoraproject.org>
Date: 02/08/2016 17:22
Subject: Re: [selinux] RE: --EXTERNAL--Welcome to the "selinux" mailing
list
On Mon, Aug 01, 2016 at 10:20:32PM +0000, Parker, Michael D. wrote:
What are you all doing/have done to boot strap your knowledge about
SELinux?
I was reasonably happy with
https://www.amazon.com/dp/B00FEFRG4O/ ,
although what I actually did was disabled unconfined on my system
and asked a lot of questions trying to put it back together. :)
--
selinux mailing list
selinux(a)lists.fedoraproject.org
https://lists.fedoraproject.org/admin/lists/selinux@lists.fedoraproject.org