All of lore.kernel.org
 help / color / mirror / Atom feed
From: Russell Coker <russell@coker.com.au>
To: Michael Graffam <michael.graffam@gmail.com>
Cc: selinux@tycho.nsa.gov
Subject: Re: New to SELinux -- any suggestions?
Date: Sun, 29 Oct 2006 16:47:54 +1000	[thread overview]
Message-ID: <200610291747.57640.russell@coker.com.au> (raw)
In-Reply-To: <1162101958.2580.10.camel@endless>

On Sunday 29 October 2006 17:05, Michael Graffam <michael.graffam@gmail.com> 
wrote:
> > If however a file could have multiple types then such analysis would be
> > impossible unless you also had rules determining which pairs of contexts
> > might be applied to one file (in which case every permitted pair of
> > contexts could be mapped to a single context in the current SE Linux
> > system for the same result).
>
> OK, that makes perfect sense. I had figured that multiple contexts would
> be allowed, to prevent the possible need of expanding the number of
> required 'base' contexts. But, I can certainly see your point about the
> difficulty of analyzing all possible combinations.

There are many types used in SE Linux, the number you see in the targeted 
policy is a small part of what is in the strict policy.

Also recently (FC5 and above) the MLS features of SE Linux have been used.  
With separate mechanisms for protecting confidentiality and integrity a 
smaller number of types is needed (previously types were used for 
confidentiality as well).

> Thanks again for your help. Would you happen to know if there is a
> document somewhere which gives a general overview of the structure of
> the SELinux mechanisms, maybe with some details on the common contexts
> and so forth?

Some of this is documented in the Fedora wiki.

-- 
russell@coker.com.au
http://etbe.blogspot.com/          My Blog

http://www.coker.com.au/sponsorship.html Sponsoring Free Software development

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2006-10-29  6:47 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-10-29  1:41 New to SELinux -- any suggestions? Michael Graffam
2006-10-29  3:31 ` Russell Coker
2006-10-29  4:30   ` Michael Graffam
2006-10-29  5:01     ` Russell Coker
2006-10-29  6:05       ` Michael Graffam
2006-10-29  6:47         ` Russell Coker [this message]
2006-10-29 16:08         ` Joshua Brindle

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200610291747.57640.russell@coker.com.au \
    --to=russell@coker.com.au \
    --cc=michael.graffam@gmail.com \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.