All of lore.kernel.org
 help / color / mirror / Atom feed
* setting up new test user domain?
@ 2001-12-18 17:01 lonnie
  2001-12-18 17:59 ` Stephen Smalley
  0 siblings, 1 reply; 24+ messages in thread
From: lonnie @ 2001-12-18 17:01 UTC (permalink / raw)
  To: SELinux Mailing

Hello All,

Since I am very new to SELinux, I hope that all of you will forgive the many 
dumb questions that I will probably end up asking.

Instead of modifying the user.te and every.te for our project, I think that it 
might be better if I simple create a new test domain and place a "test" user in 
that domain.

>From what I can understand so far, if the user does not belong to a particular 
domain then they will not have access it. 

With this in mind then if I add a user to a newly developed domain for that 
particular user and also have their HOME directory as a member if the single 
user domain then I could effectively prevent them from moving out of 
the /home/test into the /home or any other directory.

Would this be correct? If so then couls someone please help me to figure out 
how to set up a simple domain from which to begin this process?

Also, I have made a subdirectory in the selinux/domains directory because I 
have seen this in the make file as well and this will make it so that I do not 
have to modify the makefile.

All Help would be greatly appreciated,
Lonnie


--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 24+ messages in thread
* RE: setting up new test user domain?
@ 2001-12-19 19:18 Flood Randy Capt AFCA/TCAA
  2001-12-20 11:54 ` Russell Coker
  0 siblings, 1 reply; 24+ messages in thread
From: Flood Randy Capt AFCA/TCAA @ 2001-12-19 19:18 UTC (permalink / raw)
  To: SELinux


But, under certain circumstances, chrooted jails can be broken out of.
Right?  

For example, see:

http://www.bpfh.net/simes/computing/chroot-break.html

Is this information dated?  Is chroot really more reliable now?  Isn't
the whole concept of type enforcement to give an additional layer of
security in such cases?  



-----Original Message-----
From: Gary Lowder [mailto:gary@lowder.com]
Sent: Wednesday, December 19, 2001 11:56 AM
To: SELinux@tycho.nsa.gov
Subject: Re: setting up new test user domain?


Lonnie,

I hate to completely change the direction you're headed but...
Based on what you've said earlier about what you want to accomplish, it 
seems a chroot jail is what you want for your users.  Why reinvent the 
wheel?  Of course you can beat SELinux into doing what you're asking, 
but that's not really what it was designed to directly accomplish.

Largo, Florida, implemented a linux system for it's municipality workers

to use.  A base link off of which you might find lots of useful 
information is:  http://www.consultingtimes.com/Largo.html
He didn't do exactly what you're talking about, but it's not far off.

Where I would actually start, is a site to help explain and set up a 
chroot jail, one of I'm sure many sites is: 
http://www.gsyc.inf.uc3m.es/~assman/jail/1.html

I'm sure there are others out there.

With a large enough hammer it is entirely possible to beat a square peg 
into a round hole, but it's much easier to just find the round peg.

Hope this helps you accomplish your objectives.

Gary.



--
You have received this message because you are subscribed to the selinux
list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov
with
the words "unsubscribe selinux" without quotes as the message.

--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 24+ messages in thread

end of thread, other threads:[~2001-12-20 16:09 UTC | newest]

Thread overview: 24+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2001-12-18 17:01 setting up new test user domain? lonnie
2001-12-18 17:59 ` Stephen Smalley
2001-12-18 17:59   ` lonnie
2001-12-18 18:29     ` Stephen Smalley
2001-12-18 19:43       ` lonnie
2001-12-19 14:20       ` lonnie
2001-12-19 15:03         ` Stephen Smalley
2001-12-19 17:55           ` Gary Lowder
2001-12-19 19:45             ` Stephen Smalley
2001-12-19 21:08             ` lonnie
2001-12-19 18:05           ` Debian SE Linux ? Noah silva
2001-12-19 18:34             ` Stephen Smalley
2001-12-20 11:43               ` Russell Coker
2001-12-20 14:44                 ` Stephen Smalley
2001-12-20 15:34                 ` Noah silva
2001-12-20 15:46                   ` Stephen Smalley
2001-12-20 16:01                     ` Noah silva
2001-12-20 16:09                       ` Stephen Smalley
2001-12-19 18:28           ` setting up new test user domain? lonnie
2001-12-19 19:36             ` Stephen Smalley
2001-12-19 21:01               ` lonnie
2001-12-19 21:54                 ` Stephen Smalley
  -- strict thread matches above, loose matches on Subject: below --
2001-12-19 19:18 Flood Randy Capt AFCA/TCAA
2001-12-20 11:54 ` Russell Coker

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.