All of lore.kernel.org
 help / color / mirror / Atom feed
From: Paul Moore <paul.moore@hp.com>
To: Joy Latten <latten@austin.ibm.com>
Cc: redhat-lspp@redhat.com, selinux@tycho.nsa.gov,
	cpebenito@tresys.com, jbrindle@tresys.com
Subject: Re: [redhat-lspp] labeled ipsec policy
Date: Mon, 20 Nov 2006 11:24:18 -0500	[thread overview]
Message-ID: <200611201124.19292.paul.moore@hp.com> (raw)
In-Reply-To: <1164035382.17737.408.camel@faith.austin.ibm.com>

On Monday 20 November 2006 10:09 am, Joy Latten wrote:
> On Mon, 2006-11-20 at 10:00 -0500, Paul Moore wrote:
> > On Friday 17 November 2006 5:30 pm, Joy Latten wrote:
> > > The following policy enables labeled ipsec to run
> > > in enforcing mode. I configure labeled ipsec in sysadm_r role.
> > > Thus the rules I needed were specific to this role.
> >
> > I'll let the policy gurus comment on the rest of the policy, but I think
> > that we would want only the secadm_r role (in the MLS/LSPP policy) to be
> > able to configure labeled IPsec.  Yes?
>
> Actually, I wondered about this too. But when I took a look at the
> policy source, I noticed that in userdomain.te, sysadm_t was allowed
> to execute ipsec programs ipsec_exec_mgmt(sysadm_t), so I just assumed I
> should use sysadm_r role. Not sure if this was correct or not. Tried
> secadm_r role out of curiousity and got quite a lot of avc denied
> messages. So went with sysadm_r. :-)

Hmmm, I suspect this will probably be a problem as the IPsec management tools 
serve a dual purpose, they control the IPsec configuration (sysadm_r) as well 
as the policy relating to labeling SAs (secadm_r).  I guess we'll just have 
to settle for sysadm_r and deal with the fact that sysadm_r is going to have 
some control over the system's security policy in this case.

-- 
paul moore
linux security @ hp

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2006-11-20 16:24 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-11-17 22:30 labeled ipsec policy Joy Latten
     [not found] ` <200611201000.06118.pcmoore@engin.umich.edu>
2006-11-20 15:09   ` [redhat-lspp] " Joy Latten
2006-11-20 16:24     ` Paul Moore [this message]
2006-11-20 16:34       ` Casey Schaufler
2006-11-21 14:10 ` Christopher J. PeBenito
2006-11-27 20:51   ` [redhat-lspp] " Joy Latten
2006-11-29 14:59     ` Christopher J. PeBenito
2006-11-29 20:42       ` Venkat Yekkirala
2006-11-29 23:51         ` Joy Latten
2006-11-30 15:57           ` Venkat Yekkirala

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200611201124.19292.paul.moore@hp.com \
    --to=paul.moore@hp.com \
    --cc=cpebenito@tresys.com \
    --cc=jbrindle@tresys.com \
    --cc=latten@austin.ibm.com \
    --cc=redhat-lspp@redhat.com \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.