All of lore.kernel.org
 help / color / mirror / Atom feed
* Security Officer and System Administrator Separation of Duties
@ 2003-10-02 22:42 Fleischman, Eric
  2003-10-03  0:55 ` Tom
  2003-10-03 12:41 ` Stephen Smalley
  0 siblings, 2 replies; 8+ messages in thread
From: Fleischman, Eric @ 2003-10-02 22:42 UTC (permalink / raw)
  To: SELinux

I am a complete newcomer to SELinux but I did not notice any answer to my question on the Mail List Archives (though I didn't look at every entry). 

I hope to be able to configure SELinux so that it would have policies that correspond to the traditional DoD Separation of Duties with Least Privilege practice of establishing different roles/functions for Network Administrators than for Security Officers. Specifically, I'd like the Security Officer to be solely able to establish/modify accounts and passwords, establish group memberships, establish user role memberships, etc. However, the Security Officer must not be able to perform any other traditional sysadm_r:sysadm_t functions. Similarly, I want the sysadm_r:sysadm_t to no longer be able to perform the functionalities that have now become within the sole auspices of the Security Officer. Is this possible to do? If so, how can I do this? 

Thank you for your attention to this request.

--Eric


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2003-10-04  7:29 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-10-02 22:42 Security Officer and System Administrator Separation of Duties Fleischman, Eric
2003-10-03  0:55 ` Tom
2003-10-03  6:55   ` Russell Coker
2003-10-03 10:19     ` Tom
2003-10-03 11:32       ` Russell Coker
2003-10-03 14:53         ` Tom
2003-10-04  7:29           ` Russell Coker
2003-10-03 12:41 ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.