On Tue, Jan 17, 2006 at 12:14:58PM -0500, Adam Gibson wrote: > http://arstechnica.com/news.ars/post/20060113-5975.html > > From all the reading I have done it seems that configuration would be > much easier for most system admins. A utility can learn what access is > needed by monitoring the app so that you don't have to know all the > details of what the app touches to get it working for new apps. For one thing it needs kernel patches that aren't upstream, which makes it unlikely. Given it duplicates a subset of SELinux functionality, it seems somewhat pointless to divide our efforts on two solutions to the same problem instead of improving the one that upstream has already chosen. Dave