From mboxrd@z Thu Jan 1 00:00:00 1970 Message-ID: <4E5E7772.7080002@roboreus.com> Date: Wed, 31 Aug 2011 19:03:30 +0100 From: Roy Badami MIME-Version: 1.0 To: Stephen Smalley CC: selinux@tycho.nsa.gov Subject: Re: CentOS 5 RBAC References: <4E5E68DB.1030101@roboreus.com> <1314811484.6850.30.camel@moss-pluto> In-Reply-To: <1314811484.6850.30.camel@moss-pluto> Content-Type: multipart/alternative; boundary="------------060706080202050609020109" Sender: owner-selinux@tycho.nsa.gov List-Id: selinux@tycho.nsa.gov This is a multi-part message in MIME format. --------------060706080202050609020109 Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 31/08/2011 18:24, Stephen Smalley wrote: > > At least in the policy sources I am looking at, a policy type that > includes the mcs suffix causes the policy to be built with -D > enable_mcs, not -D enable_mls. Thus those roles don't get included in > the mcs policy. > Yes, you're right - clearly I need glasses :-) -- Roy Badami Roboreus Ltd 1 New Oxford Street London WC1A 1NU --------------060706080202050609020109 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable
On 31/08/2011 18:24, Stephen Smalley wrote:

At least in the policy sources I am looking at, a policy type that
includes the mcs suffix causes the policy to be built with -D
enable_mcs, not -D enable_mls.=C2=A0 Thus those roles don't get included in
the mcs policy.


Yes, you're right - clearly I need glasses :-)

--=C2=A0
Roy Badami
Roboreus Ltd
1 New Oxford Street
London WC1A 1NU

--------------060706080202050609020109-- -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.