All of lore.kernel.org
 help / color / mirror / Atom feed
* Not quite MLS.
@ 2009-08-14 21:30 rob myers
  2009-08-17 11:40 ` Stephen Smalley
  0 siblings, 1 reply; 8+ messages in thread
From: rob myers @ 2009-08-14 21:30 UTC (permalink / raw)
  To: selinux

I would like to create a login that has access to one category at the
highest sensitivity level, but in another category only has access at a
lower sensitivity level.  For example, on a system where SystemHigh is
s0-s3:c0.c3, one login could be defined as something similar to:
s0-s1:c0.c3, s2:c2.c3, s3:c3, while another login could be defined as
s0-s2:c0.c3, s3:c0.c2 .

Am I correct that MLS policy cannot support this scenario?

Is this possible under any old, current, or developmental SELinux
policy?

Would it be possible to write such a policy with the existing SELinux
user/kernel land?

Thanks for any pointers,

rob.


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2009-08-19 21:54 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2009-08-14 21:30 Not quite MLS rob myers
2009-08-17 11:40 ` Stephen Smalley
2009-08-17 21:38   ` rob myers
2009-08-18  0:40     ` Glenn Faden
2009-08-18 14:19       ` rob myers
2009-08-18 16:15       ` Paul McNabb
2009-08-19 21:53         ` Casey Schaufler
2009-08-18 14:34     ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.