Given the increasing interest in these topics around the Confined Users SIG and since I have already seen some that maybe could have used it, I thought it is worth to not only have the selinux-confined-users tag but also the su-confined-users tag.
The selinux-confined-users aims [1] …
and [1]
The su-confined-users tag shall serve a comparable purpose, but for questions about approaches and implementations with the goal to restrict or mitigate the use of su
, sudo
, SUID
, wheel
and so on (the list is not exhaustive).
@siosm FYI. @boredsquirrel you might be interested in that too.
Don’t forget that for non-ask-fedora topics, we have the confined-users tag within the Project Discussion’s security-sig . I also requested that we get a Matrix channel for obvious reasons: Issue #11993: Create Matrix Channel for Confined Users SIG: #ConfinedUsers - fedora-infrastructure - Pagure.io
Everyone interested in the topic might feel encouraged to subscribe the tag
Supplement: Wiki is adjusted.