All of lore.kernel.org
 help / color / mirror / Atom feed
* Login context for a VNC connection
@ 2012-03-06 20:37 Andy Warner
  2012-03-06 20:47 ` Stephen Smalley
  0 siblings, 1 reply; 2+ messages in thread
From: Andy Warner @ 2012-03-06 20:37 UTC (permalink / raw)
  To: SELinux

[-- Attachment #1: Type: text/plain, Size: 412 bytes --]

I am trying to configure the login context for a user connection through 
Tiger VNC. I am using RHEL6 with the MLS policy, fully updated. 
Currently I am getting:

system_u:system_r:initrc_t:SystemLow-SystemHigh

This does not seem correct. Can someone please give me information on 
hos this context is calculated and how I can configure it so the user 
receives a context of my choosing.

Thanks,

Andy Warner

[-- Attachment #2: Type: text/html, Size: 716 bytes --]

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: Login context for a VNC connection
  2012-03-06 20:37 Login context for a VNC connection Andy Warner
@ 2012-03-06 20:47 ` Stephen Smalley
  0 siblings, 0 replies; 2+ messages in thread
From: Stephen Smalley @ 2012-03-06 20:47 UTC (permalink / raw)
  To: Andy Warner; +Cc: SELinux

On Tue, 2012-03-06 at 21:37 +0100, Andy Warner wrote:
> I am trying to configure the login context for a user connection
> through Tiger VNC. I am using RHEL6 with the MLS policy, fully
> updated. Currently I am getting:
> 
> system_u:system_r:initrc_t:SystemLow-SystemHigh
> 
> This does not seem correct. Can someone please give me information on
> hos this context is calculated and how I can configure it so the user
> receives a context of my choosing. 

Most likely means that the Tiger VNC server is not labeled, thus left in
the caller's context (initrc_t), and either does not try to set the user
session context at all (i.e. no pam_selinux in its pam config) or fails
to determine a context because it is starting from a context that is not
specified as part
of /etc/selinux/$SELINUXTYPE/contexts/default_contexts.

-- 
Stephen Smalley
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2012-03-06 20:47 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-03-06 20:37 Login context for a VNC connection Andy Warner
2012-03-06 20:47 ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.