From: Dominick Grift <dac.override@gmail.com>
To: Divya Vyas <dvyas@mvista.com>
Cc: selinux <selinux@tycho.nsa.gov>
Subject: Re: Can I change default policy from targeted to minimum
Date: Fri, 11 Sep 2015 15:41:52 +0200 [thread overview]
Message-ID: <20150911134151.GA6297@x250> (raw)
In-Reply-To: <CA+=dQ-8E2jMNN0i5=Bomp3g=hkFN=_qiQ3G5UtiXU8rNm6Ap1A@mail.gmail.com>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
On Fri, Sep 11, 2015 at 05:25:39PM +0530, Divya Vyas wrote:
> Hi,
>
> I have mls and targeted policy installed on my system. I want to have a
> minimum policy with all user unconfined and nothing restricted.
>
> I took a minimum policy from selinux-policy-minium noarch rpm and kept in
> /etc/selinux folder and edit SELINUXTYPE=minimum. Is this enough to load a
> new policy .
>
> load_policy
> SELinux: Could not open policy file <=
> /etc/selinux/minimum/policy/policy.28: No such file or directory
> load_policy: Can't load policy: No such file or directory
>
> Getting this error while the policy.28 exists in the path.
>
> Please guide me to have a minimum unrestricted policy.
Looks like youre using Fedora. the "minimum" policy model is specific to
Fedora. You might be able to get support on the Fedora selinux maillist:
https://admin.fedoraproject.org/mailman/listinfo/selinux
With that said. You could try (if things break then you get to keep the pieces): sudo setenforce 0 && sudo semodule -B &&
sudo load_policy
> _______________________________________________
> Selinux mailing list
> Selinux@tycho.nsa.gov
> To unsubscribe, send email to Selinux-leave@tycho.nsa.gov.
> To get help, send an email containing "help" to Selinux-request@tycho.nsa.gov.
- --
02DFF788
4D30 903A 1CF3 B756 FB48 1514 3148 83A2 02DF F788
https://sks-keyservers.net/pks/lookup?op=get&search=0x314883A202DFF788
Dominick Grift
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
iQGcBAEBCgAGBQJV8tobAAoJENAR6kfG5xmcZc8L/R22F6gTxgCrQaOa6uZAQ+V3
G1Wyx8N31NYWJmJ4tpQCdOtKuLeNT3RTybPIGE7+W4tklAZRSob6ljpG4ySpJjO4
SaI03QDVr1L1Hn5EduZDYsEgWXr4rSbRwRbAfV7EW1G+7cKVQktV8OejLPXFLUhj
FsemqCJV44dvI8739w9T5KsmRJpVUvTDRwzlWPVWkmRk3Sj6yfPA/N2az3YAVq0B
FOV26XUqE8EmGJC4N93VqTEo+f9rH52PhTJVArzSElBdYsVsSDRrCJCuKSJd42Cr
MA1MtDu+DRwuGA0JZtEXekrKOG/6Jx/ZGKlfIwgMAqFjd3FSApWbtEpWDWvXD1Ol
i9NvOMheLi3PkyM0NUlaE73davDTbyb1hlk0h1WDFvSJCUlNYG5KVkk2metAYk5B
3NC7EYvrroqnClXq1DfQfPxFPk2KfnnB0A6I4szUK7pJyh1LXG9+BlcecbtQx8Oy
m1NC/L+9/+zv7hKl+SUMnkLimC2MrvM2qvYYMnm8aw==
=znWe
-----END PGP SIGNATURE-----
next prev parent reply other threads:[~2015-09-11 13:41 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-09-11 11:55 Can I change default policy from targeted to minimum Divya Vyas
2015-09-11 13:41 ` Dominick Grift [this message]
2015-09-11 15:45 ` Divya Vyas
2015-09-11 15:53 ` Dominick Grift
2015-09-11 16:43 ` Divya Vyas
2015-09-11 16:51 ` Dominick Grift
2015-09-11 17:11 ` Stephen Smalley
2015-09-18 23:30 ` how to run setsebool -P in chroot? Bond Masuda
2015-09-20 21:13 ` Paul Moore
2015-09-21 20:12 ` Stephen Smalley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20150911134151.GA6297@x250 \
--to=dac.override@gmail.com \
--cc=dvyas@mvista.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.