The openSUSE Tumbleweed distribution has switched to using SELinux by default.

The developers of the openSUSE project have announced the transition of the openSUSE Tumbleweed distribution, which uses a continuous version update cycle (rolling updates), to the mandatory access control system SELinux. Starting with update 20250211, SELinux in 'enforcing' mode is proposed by default for new installations of openSUSE Tumbleweed. Ready-to-use builds of openSUSE Tumbleweed minimalVM will be shipped with SELinux enabled by default.

Support for AppArmor will remain completely intact — existing configurations will continue to use AppArmor, and the installer will provide an option to enable AppArmor in new installations. For users whose systems utilize AppArmor but wish to switch to SELinux, a migration guide has been provided. The openSUSE Leap 15.x distribution will continue to use AppArmor.

The promotion of SELinux is based on a previously accepted decision to expand the use of this access management system in SUSE and openSUSE, as SELinux surpasses AppArmor in functionality and is in demand in enterprise systems. SELinux is used in Red Hat Enterprise Linux, while AppArmor is used in Ubuntu.

AppArmor is easy to configure and ties access profiles to file paths. SELinux uses a more complex but also more flexible language for describing security policies, covering various types of resources and based on the concept of labels and security contexts. SELinux allows for handling complex access control scenarios and provides detailed control over interactions between processes, while AppArmor mainly restricts itself to defining allowed actions for individual applications.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster