All of lore.kernel.org
 help / color / mirror / Atom feed
From: Ken YANG <spng.yang@gmail.com>
To: Louis Lam <lshoujun@yahoo.com>
Cc: selinux@tycho.nsa.gov
Subject: Re: Newbie: Using SELINUX to contain vmware
Date: Fri, 06 Jul 2007 19:59:00 +0800	[thread overview]
Message-ID: <468E2E84.3000105@gmail.com> (raw)
In-Reply-To: <896266.60611.qm@web34805.mail.mud.yahoo.com>

Louis Lam wrote:
> Hi Ken,
> 
> Thank you for your replies. I'll try that out.
> 
> About my system. My target is to use RHEL 5. But i have no restrictions to use FC either.
> 
> Pardon my ignorance, btw, what do you mean by the "upstream" vmware policy? Where may I be able to
> get it?

IMHO, "upstream" means reference policy svn trunk, you can get it through:

svn co http://oss.tresys.com/repos/refpolicy/trunk refpolicy

similarly, you can also user vmware[.te, .fc, .if] in EL5 policy source.


> 
> Thanks in advance,
> Louis
> 
> 
> --- Ken YANG <spng.yang@gmail.com> wrote:
> 
>> Louis Lam wrote:
>>> Hi All,
>>>
>>> I'm trying to use SELINUX to contain vmware. I'm a newbie to the "newer" modules based SELINUX
>>> under RHEL5/CenTOS5. I can see that there is a vmware.if defined but don't know how to build
>> the
>>> module vmware.pp. Not even sure if i'm on the correct track doing this. pl advice.
>> what is your system? in fedora, there is vmware module at default:
>>
>> -(:17:48:$)-> sudo semodule -l|grep vmware
>> vmware  1.1.1
>>
>> if your policy have not vmware module, you can build it from policy source:
>>
>> # cd "dir containg your vmware source policy"
>> (vmware.fc, vmware.te, vmware.if)
>>
>> # make -f /usr/share/selinux/devel/Makefile
>> (you must install selinux-policy-devel package first)
>>
>> # semodule -i vmware.pp
>> # restorecon -R -v "vmware relative directories"
>>
>>
>>> I'm trying to use SELINUX to contain the free vmplayer 2.0.0 downloadable from vmware site.
>> Has
>>> anyone succeeded in doing so? Maybe can point me to the right resources. Thanks.
>> through upstream vmware policy, i can run vmware-workstation 6 smoothly,
>> so i think vmplayer 2.0.0 is also ok.
>>
>>
>>> Thanks in Advance,
>>> Louis
>>>
>>> Send instant messages to your online friends http://uk.messenger.yahoo.com 
>>>
>>> --
>>> This message was distributed to subscribers of the selinux mailing list.
>>> If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
>>> the words "unsubscribe selinux" without quotes as the message.
>>>
>>
>> --
>> This message was distributed to subscribers of the selinux mailing list.
>> If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
>> the words "unsubscribe selinux" without quotes as the message.
>>
> 
> 
> Send instant messages to your online friends http://uk.messenger.yahoo.com 
> 


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2007-07-06 12:03 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-07-06  9:25 Newbie: Using SELINUX to contain vmware Louis Lam
2007-07-06 10:00 ` Ken YANG
2007-07-06 10:39   ` Louis Lam
2007-07-06 11:59     ` Ken YANG [this message]
2007-07-09  9:39       ` Louis Lam
2007-07-09 10:12         ` Ken YANG
2007-07-10  8:58           ` Louis Lam
2007-07-10  9:42             ` Ken YANG

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=468E2E84.3000105@gmail.com \
    --to=spng.yang@gmail.com \
    --cc=lshoujun@yahoo.com \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.