From: Daniel J Walsh <dwalsh@redhat.com>
To: Stephen Smalley <sds@tycho.nsa.gov>
Cc: Darrel Goeddel <dgoeddel@TrustedCS.com>,
Ivan Gyurdiev <ivg2@cornell.edu>,
Karl MacMillan <kmacmillan@tresys.com>,
SELinux <SELinux@tycho.nsa.gov>
Subject: Re: getseuserbyname patch
Date: Thu, 06 Oct 2005 13:10:52 -0400 [thread overview]
Message-ID: <43455A9C.7030901@redhat.com> (raw)
In-Reply-To: <1128617540.15836.141.camel@moss-spartans.epoch.ncsc.mil>
Stephen Smalley wrote:
> On Thu, 2005-10-06 at 09:52 -0400, Daniel J Walsh wrote:
>
>> Of course if I can get rid of this file, I can probably muck around with
>> the config file also.
>> As long as we don't require the flag and default to old behavior. For
>> MLS installs we can
>> put in the flag in the config file and change it to fail if the file is
>> missing.
>>
>
> Yes, that was the idea.
>
> BTW, it occurs to me that the cases are different for no seusers.conf
> versus a seusers.conf but no matching entry and no default entry. The
> latter is more dangerous to allow to default to the old behavior,
> because a simple error in the config file could cause it to skip the
> entry for the user. Is it unreasonable to always treat no match/no
> default as an error?
>
>
Ok, I was just thinking the level on no match would be SystemLow, but
that is not easy to state in policy.
So Force there to be a default/match or return error, is ok.
>> There are files in policy now that are marked config(noreplace) like
>> local.users, ports, devices etc. So I don't think this is any
>> differerent.
>>
>
> Yes, I just wasn't sure if you ultimately intend to migrate them out,
> particularly if libsemanage takes over control of all customizations.
> At that point, the files from policy are just pushed into the sandbox
> and all modifications occur within the sandbox and to the generated
> files used at runtime, not directly to any files from the policy
> package.
>
>
But they still will need to exist and be recompiled into the sandbox
correct? I would still consider these files to be policy
specific. So they would need to be in the policy try.
BTW: I would like to rename seusers.conf to seusers and put it in
/etc/selinux/TYPE/seusers
I also am upping sensitivity level to s15 and category to c255, in the
latest policy and changing the range lines appropriately.
As proposed by Steve Grubb.
As soon as a libselinux changes show up I will put in patch to
pam_selinux to allow level selection.
--
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2005-10-06 17:10 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-09-27 18:25 getseuserbyname patch Daniel J Walsh
2005-09-28 16:39 ` Stephen Smalley
2005-09-29 13:24 ` Daniel J Walsh
2005-09-29 13:35 ` Stephen Smalley
2005-09-29 15:10 ` Stephen Smalley
2005-09-29 15:23 ` Daniel J Walsh
2005-09-29 15:20 ` Stephen Smalley
2005-09-29 19:11 ` Daniel J Walsh
2005-09-29 21:21 ` Stephen Smalley
2005-10-03 15:52 ` Stephen Smalley
2005-10-03 16:29 ` Stephen Smalley
2005-10-06 13:16 ` Stephen Smalley
2005-10-06 13:27 ` Daniel J Walsh
2005-10-06 13:38 ` Stephen Smalley
2005-10-06 13:52 ` Daniel J Walsh
2005-10-06 16:52 ` Stephen Smalley
2005-10-06 17:10 ` Daniel J Walsh [this message]
2005-10-06 18:33 ` Stephen Smalley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=43455A9C.7030901@redhat.com \
--to=dwalsh@redhat.com \
--cc=SELinux@tycho.nsa.gov \
--cc=dgoeddel@TrustedCS.com \
--cc=ivg2@cornell.edu \
--cc=kmacmillan@tresys.com \
--cc=sds@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.