Home > Security > How To Install SELinux on Ubuntu 8.04 “Hardy Heron”

How To Install SELinux on Ubuntu 8.04 “Hardy Heron”

I’m really happy to announce that SELinux is now available in Ubuntu 8.04 “Hardy Heron”.  This is the result of the amazing work of the ubuntu-security and ubuntu-hardened teams, as well as the huge contributions from the folks at Tresys.  (note: SELinux will not be the default, but is available as a security option.)

If you would prefer to use SELinux over AppArmour, or if you’re just a good soul that would like to help test Ubuntu’s SELinux implementation, please read on.

Install SELinux in Ubuntu 8.04

All that is needed is to install the SELinux package, which will remove AppArmour and apply the SELinux policy.

sudo apt-get install selinux

If you run across any issues or bugs please report them against SELinux on launchpad. Welcome to a more secure Ubuntu!

Categories: Security Tags:
  1. omegamormegil
    March 18th, 2008 at 09:55 | #1

    The link to SELinux on Launchpad is broken.

  2. March 18th, 2008 at 10:07 | #2

    @omegamormegil – I’ve fixed the link, thank you.

  3. March 18th, 2008 at 18:58 | #3

    Taken from “https://wiki.ubuntu.com/HardySELinux”:
    “If using aptitude instead of apt-get, you will need to manually remove apparmor and apparmor-utils, deselect selinux-policy-dummy, and then choose selinux-policy-refpolicy.”

  4. March 20th, 2008 at 02:54 | #4

    Nice!

  5. March 20th, 2008 at 16:58 | #5

    Hi,

    Why does it want to replace 2.6.24-12-generic with 2.6.22-14-xen?

    I don’t want to downgrade to 2.6.22…

  6. March 21st, 2008 at 06:41 | #6

    @Corrin – that seems odd. Are you running Hardy with the latest updates?

  7. Palmitao1976
    March 24th, 2008 at 03:23 | #7

    Very nice posted , thx

  8. Adams
    April 4th, 2008 at 08:27 | #8

    NSA backdoor?

  9. kindloaf
    April 22nd, 2008 at 11:53 | #9

    I tried to install SELinux on Hardy SERVER (Release Candidate). However, I got the following error:

    Setting up selinux (0.2) …
    Unknown terminal: dtterm
    Check the TERM environment variable.
    Also make sure that the terminal is defined in the terminfo database.
    Alternatively, set the TERMCAP environment variable to the desired
    termcap entry.
    debconf: whiptail output the above errors, giving up!
    dpkg: error processing selinux (–configure):
    subprocess post-installation script returned error exit status 255
    Setting up selinux-policy-refpolicy-unconfined (0.0.20071214-0ubuntu3) …

    Errors were encountered while processing:
    selinux
    E: Sub-process /usr/bin/dpkg returned an error code (1)

  10. Yuhong Bao
    June 27th, 2008 at 21:19 | #10

    TERM is not set properly or Linux does not support your terminal

  11. Geo909
    November 17th, 2008 at 19:35 | #11

    @Adams:

    Sorry for the lack of knowledge but this is open source, right? How in the world could that be a backdoor?!

    • Daniel
      July 14th, 2009 at 18:09 | #12

      The CIA or the NSA has planted an agent in the development team.

  12. weiguixm
    December 5th, 2008 at 08:19 | #13

    when i tyr the command “aptitude install selinux” the system shows:


    Couldn’t find package “selinux”.However the following packages contain “selinux” in their name: libselinux1

    What’s the matter?

  13. DarkLogic
    December 26th, 2008 at 14:09 | #14

    No backdoor. NSA doesn’t want your data, they already have it. They just want to deny others access to your data.

  14. Mir Mahboob Ali Khan
    March 8th, 2009 at 22:51 | #15

    This a line of my system log. Why does it say REDHAT ????

    Mar 9 11:14:03 boss-desktop dhcdbd: message_handler: message handler not found under /com/redhat/dhcp/eth0 for sub-path eth0.dbus.get.host_name

    Is SELINUX for a desktop or for a server?

    Please clarify if this is normal.

    Thanks,

    Mir.

    • March 9th, 2009 at 05:45 | #16

      @Mir – SELinux is commonly used in both environments, both Desktop and Server. The error you’re getting doesn’t look related to SELinux though. Its coming from dhcpd.

  15. August 11th, 2009 at 03:43 | #17

    Is it available for latest ubuntu release 9.04? what are the pros and cons of using this on ubuntu?

  16. deringer
    January 14th, 2010 at 18:10 | #18

    @Indian
    SELinux—>Ubu 9.10
    this is fantastic for people who need max security

  17. OK
    May 7th, 2010 at 03:38 | #19

    Gud hint.
    But better to explain more….
    (How to use it)
    Thanx