All of lore.kernel.org
 help / color / mirror / Atom feed
* Per Domain Permissive Mode
@ 2007-06-19 14:55 Daniel J Walsh
  2007-06-19 15:13 ` Joshua Brindle
  2007-06-19 15:17 ` James Morris
  0 siblings, 2 replies; 9+ messages in thread
From: Daniel J Walsh @ 2007-06-19 14:55 UTC (permalink / raw)
  To: SE Linux

Steven mentioned in another conversion the idea of a Per Domain 
Permissive Mode.  This is something our customers are looking for. 

A few customers want to write policy to confine an application but they 
are afraid of releasing it in enforcingmode to hundreds/thousands of 
machines, and then finding out they missed a crucial code path.  The 
would like to be able to write the policy distribute it and gather AVC 
messages in for a couple of months, until they fail confident that the 
policy will work.  Currently they would have to turn all the machines to 
permissive mode or take there chances.  

Having a simple domain that would run in permissive mode while the rest 
of the machine ran enforcing would satisfy this need.

Thoughts...

Dan

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2007-06-20 13:09 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-06-19 14:55 Per Domain Permissive Mode Daniel J Walsh
2007-06-19 15:13 ` Joshua Brindle
2007-06-19 15:17 ` James Morris
2007-06-19 15:19   ` James Morris
2007-06-19 15:44     ` Karl MacMillan
2007-06-19 16:11       ` Daniel J Walsh
2007-06-20 11:43       ` Stephen Smalley
2007-06-20 11:48         ` James Morris
2007-06-20 13:09           ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.