Bastille is certainly easier to configure than SELinux because they do two very different things. Bastille Linux is a hardening script for a variety of Linux distributions. It runs through a list of questions about security on your host and based on your answers changes configuration settings to secure your host.
SELinux uses mandatory access controls like Role-Based Access Control (RBAC) and Multi-Level Security (MLS) to secure the Linux operating system. It operates on the principal of providing user, system programs and servers with the minimum amount of privilege required to perform their functions. Therefore if a program or server is compromised, then the damage that an attacker can cause is potentially limited to the program or server they have compromised.
Bastille is a powerful and flexible hardening tool but it cannot be compared to SELinux. They simply perform two very different functions.
Related Q&A from James Turnbull
A user wants to implement OSSEC on a Windows server because he has no server side Linux operating system.continue reading
Solaris 10 Trusted Extensions and SELinux are best suited to different system requirements and administrator skill sets. Our security expert explains...continue reading
Configuring spam filters Spamassassin and dspam together in the email server Postfix is easy with the resources listed by our security expert.continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.