At least in the policy sources I am looking at, a policy type
that
includes the mcs suffix causes the policy to be built with -D
enable_mcs, not -D enable_mls. Thus those roles don't get
included in
the mcs policy.
Yes, you're right - clearly I need glasses :-)
-- Roy Badami
Roboreus Ltd
1 New Oxford Street
London WC1A 1NU