All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] pptp_t vs pppd_t
@ 2012-07-03  5:43 Russell Coker
  2012-07-03 11:18 ` Daniel J Walsh
  0 siblings, 1 reply; 7+ messages in thread
From: Russell Coker @ 2012-07-03  5:43 UTC (permalink / raw)
  To: refpolicy

Is there a real benefit in having separate domains for pptp and pppd?

The access that they have is very similar and the differences are things that 
aren't so significant (EG pptp_t denied access to pppd_devpts_t:chr_file).

Also both the programs can run each other (the policy allows pppd to run pptpd 
and in my test network pptpd needs to run pppd) which limits the ability to 
create a useful separation.

I think it would be best if we merged the two domains.

-- 
My Main Blog         http://etbe.coker.com.au/
My Documents Blog    http://doc.coker.com.au/

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2012-07-03 15:20 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-07-03  5:43 [refpolicy] pptp_t vs pppd_t Russell Coker
2012-07-03 11:18 ` Daniel J Walsh
2012-07-03 11:47   ` Miroslav Grepl
2012-07-03 11:55     ` Russell Coker
2012-07-03 13:44     ` Christopher J. PeBenito
2012-07-03 11:53   ` Russell Coker
2012-07-03 15:20   ` Sven Vermeulen

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.