From: Paul Moore <paul@paul-moore.com>
To: selinux@tycho.nsa.gov, vlad halilov <vlad.halilov@gmail.com>
Subject: Re: selinux and static label for sVirt
Date: Thu, 08 May 2014 16:34:26 -0400 [thread overview]
Message-ID: <1675546.P9Rft7smSN@sifl> (raw)
In-Reply-To: <CAHw9pMX-T9CHgahLLKjAfA_tOeFuKSwniikV_-ejw3GsCOQW0Q@mail.gmail.com>
On Thursday, May 08, 2014 05:45:56 PM vlad halilov wrote:
> Hello. I trying to run kvm wih mls policy on RHEL6.5 and got strange error.
>
> Steps:
>
> 1) installing with virtulaization software bundle;
> 2) install selinux mls and some more: xorg-x11-xauth policycoreutils-python
> selinux-policy-mls netlabel_tools setools-console;
> 3) enable mls in selinux/config, set permissive mode, autorelabel fs &
> reboot;
> 4) login by root@ssh with X (permissive mode still in effect) and create vm.
>
> Now, after creating any vm, it can executed only with dynamic label. On
> trying to set static label (s0, s1 or any other with compartments) i got
> an error:
>
> 2014-05-08 13:23:06.711+0000: 1607: error
>
> :virSecuritySELinuxGenSecurityLabel:552 : unable to allocate socket
> security context 's0': Invalid argument
If you are going to use static labels with sVirt you need to specify the
entire SELinux label and not just the MLS field. I recommend searching for
the "Red Hat Enterprise Linux 6 Virtualization Security Guide" for more
information on using sVirt with RHEL6.
--
paul moore
www.paul-moore.com
next prev parent reply other threads:[~2014-05-08 20:34 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-05-08 13:45 selinux and static label for sVirt vlad halilov
2014-05-08 20:34 ` Paul Moore [this message]
2014-05-09 5:33 ` vlad halilov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1675546.P9Rft7smSN@sifl \
--to=paul@paul-moore.com \
--cc=selinux@tycho.nsa.gov \
--cc=vlad.halilov@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.