All of lore.kernel.org
 help / color / mirror / Atom feed
* using roles with mls policy
@ 2008-11-05 15:33 Andy Warner
  2008-11-05 16:18 ` Justin Mattock
  0 siblings, 1 reply; 7+ messages in thread
From: Andy Warner @ 2008-11-05 15:33 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 1334 bytes --]

I am using Fedora 9 with the MLS policy. I have been using it in 
permissive mode for a while (integrating SELinux with a DBMS and its 
objects) and now must do some work/testing in enforcing mode. As soon as 
I switch to enforcing mode I seem unable to perform any action which 
requires privilege.

What is the anticipated method to shutdown/reboot the system and to 
toggle the enforcing mode while in MLS/Enforcing? What I assumed was to 
transition to an appropriate role (sysadm_r and secadm_r respectively) 
and then issue the corresponding command (shutdown and setenforce). This 
fails and I believe my difficulty is that in both cases I need to also 
be the linux root user. There does not seem to be an obvious way to 
execute a command as the lunux root user as neither su nor sudo seem 
available while in the sysadm_r and secadm_r roles. Executing something 
like seaudit while in the auditadm_r role fails to allow me to 
authenticate as root. Despite being the correct password it continuously 
loops asking for the password.

As a related but less important question, in general, is it intended 
that a user initially have the staff_r role upon login and then 
transition to a more trusted role (i.e., secadm_r) using the newrole 
command? (as opposed to having the secadm_r upon login.

Thanks for any help,

Andy



[-- Attachment #2: Type: text/html, Size: 1532 bytes --]

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2008-11-05 22:54 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-11-05 15:33 using roles with mls policy Andy Warner
2008-11-05 16:18 ` Justin Mattock
2008-11-05 17:52   ` Andy Warner
2008-11-05 18:22     ` Andy Warner
2008-11-05 19:28       ` Justin P. Mattock
2008-11-05 20:11       ` Daniel J Walsh
2008-11-05 22:53         ` Justin Mattock

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.