All of lore.kernel.org
 help / color / mirror / Atom feed
From: Daniel J Walsh <dwalsh@redhat.com>
To: Paul Moore <paul.moore@hp.com>
Cc: SELinux <SELinux@tycho.nsa.gov>
Subject: Re: selinux-policy-mls is now available for your testing pleasure.
Date: Wed, 20 Apr 2005 10:29:14 -0400	[thread overview]
Message-ID: <4266673A.1020403@redhat.com> (raw)
In-Reply-To: <42657740.9000005@hp.com>

Paul Moore wrote:

> Daniel J Walsh wrote:
>
>> Based off STRICT policy.
>>
>> ftp://people.redhat.com/dwalsh/SELinux/Fedora/selinux-policy-mls-*
>>
>> It is not in Rawhide, yet but I will provide it via my people page.
>>
>> This has not been tested.
>> I have not got an MLS machine up and running yet.
>
>
> Since I have been looking into this lately I figured I would give it a 
> whirl and report back my experiences, here they are:
>
>  1 Installed FC4T2 via the 'Workstation' option using two partitions,
>    one for '/' and one for swap
>  2 Applied all of the related updates via YUM (done on April 19th)
>  3 Installed the MLS policy (version 1.23-11-2) but continued to use
>    the default targeted policy
>  4 Rebooted into kernel 2.6.11-1.1240_FC4smp to verify everything was
>    OK (it was)
>  5 Enabled the MLS policy via the Fedora GUI tool and ensured that the
>    relabel option was selected
>  6 Rebooted with the new MLS policy only to have the machine lock,
>    it wasn't able to execute something related to init (I should have
>    taken better notes here - sorry)
>  7 Rebooted (the hard way, Ctrl-Alt-Del only resulted in more AVC
>    denial messages) with 'selinux=0 single'
>  8 Unmounted '/proc' and '/sys' then relabeled them to
>    'system_u:object_r:file_t:s0' and 'user_u:object_r:file_t:s0'
>    respectively; also relabeled '/var/lib/nfs/rpc_pipefs' to
>    'user_u:object_r:var_lib_nfs_t:s0'
>  9 Rebooted with 'enforcing=0 single' and this time the FS-wide
>    relabel happened as part of the boot process
> 10 Rebooted with 'single' and noticed lots of permission denied
>    messages pertaining to '/dev/.udevdb/*' files

udevdb/* files should be labeled udev_tbl_t  Accordiung to policy

> 11 Switched to runlevel 3 and saw a variety of AVC denial messages but
>    things went mostly to plan and I had a login prompt which appeared
>    to work as expected
> 12 Rebooted normally, i.e. 'rhgb quiet 5', and X failed to start
>
> I'm going to keep playing with this system, but I thought some people 
> here might want to see a quick little report on how the MLS policy RPM 
> worked.
>
Could you clear you /var/log/messages or /var/log/audit/audit.log file.  
Reboot and then send the AVC messages.

Dan

-- 



--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  parent reply	other threads:[~2005-04-20 14:29 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-04-15 21:04 selinux-policy-mls is now available for your testing pleasure Daniel J Walsh
2005-04-19 21:25 ` Paul Moore
2005-04-19 22:29   ` James Morris
2005-04-20 12:07     ` Stephen Smalley
2005-04-20 13:11       ` Paul Moore
2005-04-20 17:04         ` Paul Moore
2005-04-20 17:50           ` Stephen Smalley
2005-04-20 14:29   ` Daniel J Walsh [this message]
2005-04-20 17:47     ` Paul Moore
2005-04-21 20:33 ` Paul Moore
2005-04-21 21:41   ` Paul Moore
  -- strict thread matches above, loose matches on Subject: below --
2005-04-20 12:54 Paul Moore
2005-04-20 18:12 jrdesai18-tech
2005-04-20 18:44 ` Paul Moore

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4266673A.1020403@redhat.com \
    --to=dwalsh@redhat.com \
    --cc=SELinux@tycho.nsa.gov \
    --cc=paul.moore@hp.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.