All of lore.kernel.org
 help / color / mirror / Atom feed
* SELinux role separation
@ 2011-01-18 18:03 Qwyjibo Jones
  2011-01-19 19:29 ` Stephen Smalley
  2011-01-19 20:11 ` Daniel J Walsh
  0 siblings, 2 replies; 12+ messages in thread
From: Qwyjibo Jones @ 2011-01-18 18:03 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 1395 bytes --]

I am currently working with an Itanium2 system which has RHEL 5.3 MLS
installed.
I am trying to understand how separation of roles works in SELinux/MLS
policy version 21. We have been told that we need to separate roles that the
sys admin is no longer allowed to do.

After reading through these threads, in the archives I am still wondering
about a couple things:

http://www.nsa.gov/research/selinux/list-archive/0504/thread_body66.shtml#11082

And this one:
http://www.nsa.gov/research/selinux/list-archive/0802/thread_body60.shtml

1) Is the RHEL 5.x MLS policy version 21 capable of the following separation
of sysadm_r and secadm_r roles:

   a) Can the secadm_r role be the only role that can assign roles via
semanage?

   b) Can the secadm_r role be the only role that can assign/modify network
interface labels via semanage?

   c) Can the secadm_r role be the only role that can control files used in
auditing, like auditd.conf. audit.rules, /etc/init.d/auditd etc...

2) Is this better accomplished with a combination of SUDO and SELinux?
3) How can I determine what secadm_r can do in the current configuration?
can any of the CLI tools show me that? ( no gui tools available )

If not, what about RHEL 6 ? ( I understand RHEL 6 is not available to
Itanium systems, but we may have new hardware soon)

Any tips. hints, pointers etc... would be very helpfull.

Thanks for your time,

[-- Attachment #2: Type: text/html, Size: 1730 bytes --]

^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2011-02-19 14:26 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-01-18 18:03 SELinux role separation Qwyjibo Jones
2011-01-19 19:29 ` Stephen Smalley
2011-01-19 20:11 ` Daniel J Walsh
2011-01-19 21:44   ` Qwyjibo Jones
2011-01-19 21:47     ` Daniel J Walsh
2011-01-19 21:51     ` Daniel J Walsh
2011-01-20 13:43       ` Qwyjibo Jones
2011-01-20 13:45       ` Qwyjibo Jones
2011-01-20 14:21         ` Daniel J Walsh
2011-01-20 14:23         ` Daniel J Walsh
2011-01-20 17:05           ` Qwyjibo Jones
2011-02-19 14:25             ` Qwyjibo Jones

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.