From: Daniel J Walsh <dwalsh@redhat.com>
To: Todd Miller <Tmiller@tresys.com>
Cc: Stephen Smalley <sds@tycho.nsa.gov>,
Stefan Schulze Frielinghaus <stefan@seekline.net>,
SE Linux <selinux@tycho.nsa.gov>
Subject: Re: Resend: Sudo Changes for SELinux
Date: Thu, 07 Feb 2008 12:20:36 -0500 [thread overview]
Message-ID: <47AB3DE4.6040308@redhat.com> (raw)
In-Reply-To: <6FE441CD9F0C0C479F2D88F959B015880181F2A3@exchange.columbia.tresys.com>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Todd Miller wrote:
> Daniel J Walsh wrote:
>> I don't recall, I wrote it several years ago. I guess the simplest
>> thing is to try it out, without the fork.
>
> Seems to work fine without the fork. I've made quite a few changes and
> you can now specify sudoers lines like:
>
> tmiller ALL=(ALL) ROLE=sysadm_r TYPE=sysadmin_t /bin/sh
>
> and have it do what (I think) you want. Note that "make install" does
> not currently set the label on sesh, perhaps it should. I'm also not
> sure that /usr/sbin is the best place for sesh. My inclination would be
> to put it in /usr/libexec, though this is not a big deal.
>
> - todd
You are the boss. Move it to /usr/libexec. And I will fix policy to
label it correctly. I would not put SELinux awareness into the install,
that is either "install", rpm. dpkg problem.
I look forward to testing it out. And once it is in Rawhide, will blog
about how to use it with SELinux.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.8 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org
iEYEARECAAYFAkerPeQACgkQrlYvE4MpobM0dgCgsVNlzSmComL5m39JExgG0cjj
Z3gAoJ1GydVEoFvHUf4CNvgjNhZNoygg
=grpX
-----END PGP SIGNATURE-----
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2008-02-07 17:20 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-01-09 16:01 Sudo Changes for SELinux Daniel J Walsh
2008-01-09 17:51 ` Todd Miller
2008-01-09 18:23 ` Stephen Smalley
2008-01-10 19:23 ` Daniel J Walsh
2008-01-10 20:01 ` Stefan Schulze Frielinghaus
2008-01-11 14:37 ` Daniel J Walsh
2008-01-11 15:32 ` Stephen Smalley
2008-01-11 15:38 ` Stephen Smalley
2008-01-11 16:45 ` Daniel J Walsh
2008-01-11 19:10 ` Daniel J Walsh
2008-01-30 14:52 ` Resend: " Daniel J Walsh
2008-01-31 0:35 ` Accurately setting Security Context of a user when ssh-ing in Hasan Rezaul-CHR010
2008-01-31 0:30 ` Dave Quigley
2008-02-05 0:44 ` Hasan Rezaul-CHR010
2008-02-05 13:01 ` Stephen Smalley
2008-02-07 4:13 ` Hasan Rezaul-CHR010
2008-02-07 14:16 ` Stephen Smalley
[not found] ` <D06FE0A2807BC145B0D38744789D4F5D045B7963@de01exm68.ds.mot.com>
[not found] ` <1202842666.24250.112.camel@moss-spartans.epoch.ncsc.mil>
2008-02-12 23:01 ` Hasan Rezaul-CHR010
2008-02-13 14:38 ` Stephen Smalley
2008-02-13 20:02 ` Hasan Rezaul-CHR010
2008-02-13 20:23 ` Stephen Smalley
2008-02-14 15:05 ` Stephen Smalley
2008-02-06 14:59 ` Resend: Sudo Changes for SELinux Todd Miller
2008-02-06 15:28 ` Daniel J Walsh
2008-02-07 17:03 ` Todd Miller
2008-02-07 17:20 ` Daniel J Walsh [this message]
2008-02-07 17:51 ` Todd Miller
2008-02-19 19:47 ` Daniel J Walsh
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=47AB3DE4.6040308@redhat.com \
--to=dwalsh@redhat.com \
--cc=Tmiller@tresys.com \
--cc=sds@tycho.nsa.gov \
--cc=selinux@tycho.nsa.gov \
--cc=stefan@seekline.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.