From: Paul Moore <paul.moore@hp.com>
To: Joshua Brindle <jbrindle@tresys.com>
Cc: Venkat Yekkirala <vyekkirala@TrustedCS.com>,
Joy Latten <latten@austin.ibm.com>,
latten@us.ibm.com, sds@tycho.nsa.gov, selinux@tycho.nsa.gov
Subject: Re: ipsec and getpeercon()
Date: Tue, 05 Sep 2006 11:15:32 -0400 [thread overview]
Message-ID: <44FD9494.8040108@hp.com> (raw)
In-Reply-To: <1157457204.15886.7.camel@twoface.columbia.tresys.com>
Joshua Brindle wrote:
> On Tue, 2006-09-05 at 00:00 -0400, Paul Moore wrote:
>
>>On Monday 04 September 2006 2:51 pm, Joshua Brindle wrote:
>>
>>>On Fri, 2006-09-01 at 18:32 -0400, Paul Moore wrote:
>>>
>>>>Paul Moore wrote:
>>>>
>>>>>Venkat Yekkirala wrote:
>>>>>
>>>>>>>Unfortunately, the fix
>>>>>>>is not immediately obvious.
>>>>>>
>>>>>>You would use the xfrm_sid and in it's absence the node
>>>>>>sid as the base sid.
>>>>>
>>>>>That is not the issue I am dealing with right now.
>>>>>
>>>>>I now have a solution in mind, however, it is doubtful I will have a
>>>>>chance to do any sort of testing on it before I leave tonight. Once I
>>>>>can give it a quick test to verify that it doesn't break anything I'll
>>>>>post a patch for you and Joy to verify.
>>>>
>>>>Sorry for attaching the patch as an attachment but I'm in a rush to get
>>>>out of here ...
>>>>
>>>>This patch is against David Miller's net-2.6.19 tree from a day or two
>>>>ago, depending on your kernel you may have some fuzz when applying this
>>>>patch. I've only done some quick functional tests, but it seems to
>>>>solve this problem.
>>>>
>>>>Joy, Venkat if you are able to test this and let me know the results I
>>>>would appreciate it.
>>>>
>>>>Thanks.
>>>
>>>I tried the (rebased patch below, there were some rejects when applying
>>>it to todays net-2.6.19) and got the same behavior as before:
>>>
>>>[root@joker-rawhide-clone ~]# ./server
>>>server: got connection from 10.1.13.104, root:system_r:unconfined_t:s0
>>>
>>>[root@joker-rawhide-clone ~]# runcon -t passwd_t ./server
>>>server: got connection from 10.1.13.104, root:system_r:passwd_t:s0
>>
>>Thanks for giving the patch a try. I'm confused as to why it didn't work for
>>you, can you try it without IPsec configured to see what results you get
>>(that is what I did and it worked fine)?
>>
>>Thanks.
>
>
> Or it could just be that I'm retarded and booted up on the wrong kernel
> after cloning the VM. The new results (with no SAD or SPD entries) is a
> nice "Protocol not available" on both sides. With the entries I now get
Glad to see I'm not the only one who boots old kernels, personally I
like to blame those pesky, meddling sunspots ;)
> server: got connection from 10.1.13.104, system_u:object_r:unlabeled_t
>
> which is the correct label of the local ipsec socket (changed it to make
> sure it was getting the local context) which still isn't what I'd expect
> getpeercon() to tell me.
--
paul moore
linux security @ hp
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2006-09-05 15:15 UTC|newest]
Thread overview: 59+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-09-01 20:49 ipsec and getpeercon() Venkat Yekkirala
2006-09-01 20:58 ` Paul Moore
2006-09-01 22:32 ` Paul Moore
2006-09-04 18:51 ` Joshua Brindle
2006-09-05 4:00 ` Paul Moore
2006-09-05 11:53 ` Joshua Brindle
2006-09-05 15:15 ` Paul Moore [this message]
-- strict thread matches above, loose matches on Subject: below --
2006-09-06 16:20 Venkat Yekkirala
2006-09-06 16:19 Venkat Yekkirala
2006-09-05 20:04 Venkat Yekkirala
2006-09-05 20:01 Venkat Yekkirala
2006-09-06 15:55 ` Joshua Brindle
2006-09-05 16:42 Venkat Yekkirala
2006-09-05 17:10 ` Paul Moore
2006-09-05 16:27 Venkat Yekkirala
2006-09-05 16:14 Venkat Yekkirala
2006-09-05 16:27 ` Paul Moore
2006-09-05 15:43 Venkat Yekkirala
2006-09-05 16:01 ` Paul Moore
2006-09-05 14:36 Joy Latten
2006-09-01 22:42 Joy Latten
2006-09-01 20:35 Venkat Yekkirala
2006-09-04 12:38 ` Joshua Brindle
2006-09-01 19:52 Joy Latten
2006-09-01 19:47 Joy Latten
2006-09-01 20:19 ` Paul Moore
2006-09-04 12:43 ` Joshua Brindle
2006-09-05 3:32 ` Paul Moore
2006-09-05 11:58 ` Joshua Brindle
2006-09-05 13:31 ` Stephen Smalley
2006-09-05 13:34 ` Joshua Brindle
2006-09-05 15:24 ` Paul Moore
2006-09-05 15:22 ` Paul Moore
2006-09-01 19:41 Venkat Yekkirala
2006-09-01 19:34 Venkat Yekkirala
2006-09-01 18:17 Joy Latten
2006-09-01 15:49 Venkat Yekkirala
2006-09-01 16:52 ` Stephen Smalley
2006-09-01 17:48 ` Joshua Brindle
2006-09-01 14:35 Venkat Yekkirala
2006-09-01 15:25 ` Joshua Brindle
2006-09-01 15:40 ` Paul Moore
2006-09-04 12:59 ` Joshua Brindle
2006-09-05 3:50 ` Paul Moore
2006-09-01 13:16 Venkat Yekkirala
2006-09-01 13:41 ` Stephen Smalley
2006-08-30 16:43 Venkat Yekkirala
2006-09-01 12:15 ` Joshua Brindle
2006-08-29 18:08 Joshua Brindle
2006-08-29 18:20 ` Joshua Brindle
2006-08-29 18:28 ` Paul Moore
2006-08-29 19:28 ` Paul Moore
2006-08-29 19:37 ` Stephen Smalley
2006-08-29 19:46 ` Joshua Brindle
2006-08-29 20:25 ` Stephen Smalley
2006-08-29 20:32 ` Stephen Smalley
2006-08-29 21:11 ` Klaus Weidner
2006-08-30 11:28 ` Stephen Smalley
2006-08-29 22:37 ` Joshua Brindle
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=44FD9494.8040108@hp.com \
--to=paul.moore@hp.com \
--cc=jbrindle@tresys.com \
--cc=latten@austin.ibm.com \
--cc=latten@us.ibm.com \
--cc=sds@tycho.nsa.gov \
--cc=selinux@tycho.nsa.gov \
--cc=vyekkirala@TrustedCS.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.