From: Luke Kenneth Casson Leighton <lkcl@lkcl.net>
To: Valdis.Kletnieks@vt.edu
Cc: Stephen Smalley <sds@epoch.ncsc.mil>, SE-Linux <selinux@tycho.nsa.gov>
Subject: Re: [idea] multiple contexts.
Date: Tue, 27 Jul 2004 22:49:11 +0100 [thread overview]
Message-ID: <20040727214911.GA23371@lkcl.net> (raw)
In-Reply-To: <200407272123.i6RLNcp9016219@turing-police.cc.vt.edu>
On Tue, Jul 27, 2004 at 05:23:38PM -0400, Valdis.Kletnieks@vt.edu wrote:
> On Tue, 27 Jul 2004 22:28:36 BST, Luke Kenneth Casson Leighton said:
>
> > yes, sort-of: more that i only wish to limit what programs a user
> > can run (and what programs _those_ programs can run).
> >
> > in particular, i want to stop people from being able to use the
> > "Run" capability of Konqueror, etc. STOP, not have the popup coming
> > up with "are you sure you want to run this program?".
>
> Do these users have anything resembling shell access? If they can get an xterm
> or an editor open, they can run the program *anyhow*....
no, xterm will not be on the list of programs they can run :)
when i say it'll be a list of programs that they can run i MEAN
if it ain't on the list it ain't gonna run.
i.e. it's mandatory access control,
> Probably easier to do the kdeuser group and start chgrp'ing, than to try to fight THAT
> war.
>
> Or see how hard it would be to create a patch to Konqueror to disable the
> button, and see if you can push it upstream...
there are more places, there are more programs.
other programs, such as ksmoothdock, such as Basket, such as kxdocker,
such as KMenu being edited and people manually putting programs onto
their menus.
all of these things i just don't wanna know about _how_ they are run:
if they ain't on the list, splat.
make a user a member of kdeusers + chgrp-to-kdeusers + 0660 on all
exes in the "allowed list" is my "fallback" position.
i'd just rather it wasn't the only position.
l.
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2004-07-27 21:38 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-07-24 23:11 [idea] multiple contexts Luke Kenneth Casson Leighton
2004-07-25 0:17 ` Russell Coker
2004-07-26 16:12 ` Stephen Smalley
2004-07-27 16:06 ` Luke Kenneth Casson Leighton
2004-07-27 17:33 ` Stephen Smalley
2004-07-27 18:23 ` Luke Kenneth Casson Leighton
2004-07-28 23:16 ` Erich Schubert
2004-07-29 1:00 ` Luke Kenneth Casson Leighton
2004-07-27 19:40 ` Valdis.Kletnieks
2004-07-27 21:28 ` Luke Kenneth Casson Leighton
2004-07-27 21:23 ` Valdis.Kletnieks
2004-07-27 21:49 ` Luke Kenneth Casson Leighton [this message]
2004-07-28 12:33 ` David Caplan
2004-07-28 14:37 ` Luke Kenneth Casson Leighton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20040727214911.GA23371@lkcl.net \
--to=lkcl@lkcl.net \
--cc=Valdis.Kletnieks@vt.edu \
--cc=sds@epoch.ncsc.mil \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.