All of lore.kernel.org
 help / color / mirror / Atom feed
From: Daniel J Walsh <dwalsh@redhat.com>
To: selinux@tycho.nsa.gov
Cc: Russell Coker <russell@coker.com.au>
Subject: Re: SELinux version of sudo
Date: Wed, 16 Apr 2003 06:33:07 -0400	[thread overview]
Message-ID: <3E9D3163.9040807@redhat.com> (raw)
In-Reply-To: <200304161408.06042.russell@coker.com.au>

[-- Attachment #1: Type: text/plain, Size: 1798 bytes --]



Russell Coker wrote:

>On Wed, 16 Apr 2003 03:33, Stephen Smalley wrote:
>  
>
>>The idea of merging su and newrole has been suggested on the list
>>previously; please be sure that you have read the earlier discussions
>>and are aware of the potential risks, e.g. see the thread starting at
>>http://marc.theaimsgroup.com/?l=selinux&m=102643997004008&w=2, so that
>>you can avoid common pitfalls.
>>    
>>
>
>That thread did not entirely convince me not to do it, but did convince me 
>that it would take much of consideration and testing, and that there were 
>more important things to spend time on.
>
>Another potential solution to this issue is to allow the administrators in 
>question to ssh into an account with UID=0 and then they only need to use 
>newrole to get all the privs they need.
>
>  
>
>>via allow rules.  It isn't clear that you should be using the existing
>>$1_su_t domain for this purpose, unless you are also patching su to
>>provide this functionality and to ensure that it does not allow
>>    
>>
>
>I agree.  The $1_su_t domain only makes sense when you are limiting the 
>transitions to a certain set of domains.  If you grant the su/sudo program 
>privrole access then there is no benefit in having more than one domain in 
>the way it is currently done.
>
>Maybe we should work from the other direction and consider adding setuid() 
>support to newrole?
>  
>
I like the idea of combining DAC with MAC using sudo rather than 
su/newrole.  This would allow
an administrator to allow other people run functions that require 
greater access to the system without them
having to have the root password.   IE.  You could allow someone to 
manage the printers database without
having to become root.  Doing all MAC becomes to combersome for this 
type of thing.

>  
>

[-- Attachment #2: Type: text/html, Size: 2437 bytes --]

  reply	other threads:[~2003-04-16 10:33 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-04-15 14:32 SELinux version of sudo Daniel J Walsh
2003-04-15 17:33 ` Stephen Smalley
2003-04-15 18:28   ` Daniel J Walsh
2003-04-16  4:08   ` Russell Coker
2003-04-16 10:33     ` Daniel J Walsh [this message]
2003-04-16 12:21       ` Russell Coker

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=3E9D3163.9040807@redhat.com \
    --to=dwalsh@redhat.com \
    --cc=russell@coker.com.au \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.