All of lore.kernel.org
 help / color / mirror / Atom feed
From: Ken YANG <spng.yang@gmail.com>
To: "Christopher J. PeBenito" <cpebenito@tresys.com>
Cc: Stephen Smalley <sds@tycho.nsa.gov>,
	SELinux List <selinux@tycho.nsa.gov>,
	Daniel J Walsh <dwalsh@redhat.com>
Subject: Re: three problems about normal user login in strict policy
Date: Wed, 13 Jun 2007 10:32:06 +0800	[thread overview]
Message-ID: <466F5726.1090901@gmail.com> (raw)
In-Reply-To: <1181242131.6578.96.camel@sgc.columbia.tresys.com>

[-- Warning: decoded text below may be mangled, UTF-8 assumed --]
[-- Attachment #1: Type: text/plain; charset=GB18030, Size: 2564 bytes --]


thanks for all of your reply.

i am learning walsh blog, i hope i can figure out all points
about user management in SELinux through all of your replies,
walsh blog, policy source, and etc...

anyway, thanks again


Christopher J. PeBenito wrote:
> On Thu, 2007-06-07 at 09:54 -0400, Stephen Smalley wrote:
>> On Thu, 2007-06-07 at 13:47 +0000, Christopher J. PeBenito wrote:
>>> On Thu, 2007-06-07 at 09:34 -0400, Stephen Smalley wrote:
>>>> On Thu, 2007-06-07 at 20:22 +0800, Ken YANG wrote:
>>>>> i studied the point from walsh about non-root X login,
>>>>> see details in following thread:
>>>>>
>>>>> http://marc.info/?l=selinux&m=118050940823692&w=2
>>>>>
>>>>> when i login with normal user(user_u), i have some questions:
>>>>> (i'm in fc7 with strict-mcs policy at svn version 2301)
>>>>>
>>>>> 1
>>>>> when i login as user_u, i find i can not switch to staff_u through su,
>>>>> but i notice that there is corresponding line in "default_contexts" file:
>>>> The su / pam_selinux integration was reverted a while ago, so su no
>>>> longer changes contexts at all, just like in the original SELinux.  
>>>> Thus, the SELinux user identity is once again stable for the entire
>>>> session, and you have to use newrole to switch roles.  And user_r isn't
>>>> generally allowed to switch to staff_r; you need to map your Linux user
>>>> identity to staff_u via semanage.
>>>>
>>>>> user_r:user_su_t:s0     staff_r:staff_t:s0 user_r:user_t:s0
>>>>> sysadm_r:sysadm_t:s0
>>>>>
>>>>> and in the policy, i found the condition of su domain transition have
>>>>> satisfied, including su_exec_t entrypoint and type_transition rules,
>>>>> furthermore, i also meet the constrain conditon in
>>>>> su_per_role_template(), e.g. domain_role_change_exemption($1_su_t),
>>>>> domain_subj_id_change_exemption($1_su_t),
>>>>> domain_obj_id_change_exemption($1_su_t), and etc.
>>>> Hmm...seems like those should be removed from policy (unless some distro
>>>> tunable is set for older fedora or rhel4), as su should no longer be
>>>> making such transitions.
>>> Its in a rhel4 build option.
>> Hmmm...so why is it still showing up in F7 strict policy?
> 
> He's just looking at the su.if header (hence the $1_su_t references),
> which is just copied out of the refpolicy sources as is.  So its in the
> headers, but shouldn't be in the actual policy.
> 


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2007-06-13  2:35 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-06-07 12:22 three problems about normal user login in strict policy Ken YANG
2007-06-07 13:34 ` Stephen Smalley
2007-06-07 13:47   ` Christopher J. PeBenito
2007-06-07 13:54     ` Stephen Smalley
2007-06-07 18:48       ` Christopher J. PeBenito
2007-06-13  2:32         ` Ken YANG [this message]
2007-06-19  7:57         ` Ken YANG
2007-06-19 11:51           ` Stephen Smalley
2007-06-19 12:09             ` Christopher J. PeBenito
2007-06-20  6:18             ` Ken YANG
2007-06-20 10:37               ` Daniel J Walsh
2007-06-20 11:40                 ` Ken YANG

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=466F5726.1090901@gmail.com \
    --to=spng.yang@gmail.com \
    --cc=cpebenito@tresys.com \
    --cc=dwalsh@redhat.com \
    --cc=sds@tycho.nsa.gov \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.