All of lore.kernel.org
 help / color / mirror / Atom feed
* Default Policy question?
@ 2003-06-02 16:04 Daniel J Walsh
  2003-06-02 17:21 ` Stephen Smalley
                   ` (2 more replies)
  0 siblings, 3 replies; 10+ messages in thread
From: Daniel J Walsh @ 2003-06-02 16:04 UTC (permalink / raw)
  To: SELinux

Has anyone discussed the problem of having root be a member of the 
sysadm_r role.  Is there a way to define policy such that you could
allow a sysadmin to manipulate configuration without allowing them to
effect policy?  Ie, does the default policy allow someone the ability to
change the /etc/printcap file but not run load_policy?  Should we have 
three levels of user by default.  My problem with this is that 
sysadmin's are going to become root and run newrole to sysadm_r to 
manipulate configuration.  If they stay newrole and run a trojaned app,
security is compromized.

user_r    - Very little privs for general users
sysadm_r  - Ability to manipulate all standard Linux config files.
policy_r  - Ability to change the way the kernel handles policy. 
(/etc/security/selinux/*, /etc/grup.conf, chsid, avc_toggle ...)

policy_r should not be defaulted to the root user but garnered in some 
other way.

Anyone have any ideas on this?


Dan


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2003-06-03 17:20 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-06-02 16:04 Default Policy question? Daniel J Walsh
2003-06-02 17:21 ` Stephen Smalley
2003-06-02 21:03   ` Tom
2003-06-02 23:51     ` Russell Coker
2003-06-03  6:30       ` Tom
2003-06-03 13:31         ` Russell Coker
2003-06-03 12:20     ` Stephen Smalley
2003-06-03 17:20       ` Tom
2003-06-02 18:11 ` Tom
2003-06-02 20:22 ` Frank Mayer

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.