All of lore.kernel.org
 help / color / mirror / Atom feed
* Best base policy to use
@ 2011-07-05 22:11 Jeremiah Jahn
  2011-07-06  6:09 ` Dominick Grift
  2011-07-06  8:10 ` Russell Coker
  0 siblings, 2 replies; 8+ messages in thread
From: Jeremiah Jahn @ 2011-07-05 22:11 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 832 bytes --]

So I'm in the process of Upgrading my servers from RHEL5 to RHEL6. On my
RHEL5 system I had to build the reference policy from scratch in order to
prevent users from being able to  transition to init_t through initrc_t.
Basically, I want systems that have to be rebooted in order to restart
certain services, like auditd, or at least be able to split those duties
into different roles. One role can edit a file or install something, but a
different role must restart it. Because life the universe and everything
goes through initrc_t, just about anything on the system running as root can
mess with services. I'd like to highly limit things, and haven't  really
looked at any new developments in selinux for about 4 years. What's the best
way/place to start removing domain transitions and requiring additional
roles.

thanks,
-jj-

[-- Attachment #2: Type: text/html, Size: 865 bytes --]

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2011-07-07 14:19 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-07-05 22:11 Best base policy to use Jeremiah Jahn
2011-07-06  6:09 ` Dominick Grift
2011-07-06 13:59   ` Jeremiah Jahn
2011-07-06 14:11     ` Dominick Grift
2011-07-07 13:46       ` Jeremiah Jahn
2011-07-07 14:19         ` Christopher J. PeBenito
2011-07-06  8:10 ` Russell Coker
2011-07-06 14:14   ` Jeremiah Jahn

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.