All of lore.kernel.org
 help / color / mirror / Atom feed
* new to selinux
@ 2014-01-10  9:16 Bryan Harris
  2014-01-10  9:33 ` Ilya Frolov
  2014-01-10 14:44 ` Stephen Smalley
  0 siblings, 2 replies; 12+ messages in thread
From: Bryan Harris @ 2014-01-10  9:16 UTC (permalink / raw)
  To: selinux@tycho.nsa.gov

Hello,

I'm wondering if it is possible to use selinux network & process labeling, iptables, and something like /usr/bin/script to create an environment where we can enforce session recording for ssh sessions.

We will soon have a requirement to record our actions on customer environments, but at the same time we also need to block users who have not activated the recording.  Is selinux policy an appropriate way to accomplish these requirements?  I'd like to search for the details and learn more, but if I'm taking the wrong approach I'd like to know that before starting out.

Any guidance is greatly appreciated.  Thanks in advance.

V/r,
Bryan

^ permalink raw reply	[flat|nested] 12+ messages in thread
* new to selinux
@ 2005-08-10 15:48 nitin kanaskar
  2005-08-10 16:46 ` Stephen Smalley
  0 siblings, 1 reply; 12+ messages in thread
From: nitin kanaskar @ 2005-08-10 15:48 UTC (permalink / raw)
  To: selinux


hi all...
i ve started reading selinux papers
and am interested in contributing
in any area listed in the section
'remaining work' of the site.
Could anybody provide any suggestions?

Regards
Nitin

_________________________________________________________________
Logon to MSN Games http://www.msngamez.com/in/gamezone/ Enjoy unlimited 
action


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 12+ messages in thread
* Re: New to SELinux
@ 2002-08-22 19:03 M. H.
  0 siblings, 0 replies; 12+ messages in thread
From: M. H. @ 2002-08-22 19:03 UTC (permalink / raw)
  To: sds; +Cc: selinux

>For example, the next NSA release should include the new sock
>hooks, a reliable accept_secure implementation

When is the next release expected to come out?

Thanks,

M.H.

_________________________________________________________________
Join the world’s largest e-mail service with MSN Hotmail. 
http://www.hotmail.com


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 12+ messages in thread
* RE: New to SELinux
@ 2002-08-19 21:26 Westerman, Mark
  2002-08-20 11:37 ` Stephen Smalley
  0 siblings, 1 reply; 12+ messages in thread
From: Westerman, Mark @ 2002-08-19 21:26 UTC (permalink / raw)
  To: Jeremy Kusnetz, 'SELinux@tycho.nsa.gov'

on Monday, August 19, 2002 3:47 PM, Russell Coker wrote:

> They always have new releases long before the NSA does. Steve often
releases 
> patches that will apply on top of the LSM release or the NSA release to
add 
> new SE Linux support.  I include these patches in my Debian package, so
the 
> Debian packages I release are the most current single release  files you
can 
> get.  I have them on my web site at 
> http://www.coker.com.au/selinux/kern/ .
> 
The Sourceforge cvs tree is up to date. Every patch for SELinux Steve
updates, he
updates the sourceforge CVS tree.  The sourceforge cvs tree is the updated
NSA release.
When the NSA Releases a new release the sourceforge will be updated at about
the same
time. If you wish to follow close to the NSA releases use the sourceforge
cvs tree,
it only contains patches that have been applied to the SELinux project. 

http://sourceforge.net/projects/selinux/

Mark

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 12+ messages in thread
* New to SELinux
@ 2002-08-19 20:33 Jeremy Kusnetz
  2002-08-19 20:47 ` Russell Coker
  2002-08-20 10:51 ` Stephen Smalley
  0 siblings, 2 replies; 12+ messages in thread
From: Jeremy Kusnetz @ 2002-08-19 20:33 UTC (permalink / raw)
  To: 'SELinux@tycho.nsa.gov'

I've been reading SELinux documentation and getting ready to try to deploy
it on a system.

A couple of questions.  Are there any up to date archives of this mailing
list other then what's on NSA's site, since it doesn't get updated daily
(last update on July 3rd)?

Second, I got a scared and read a slashdot article from today saying that
NSA is no longer developing SELinux due to lobbying from  Microsoft because
the government is competing against private American companies.  Is this
true?  Is SELinux still being developed?  Is it still being developed by
NSA, or someonen else now.

If it is still being developed, is there an SELinux patch to the 2.4.19
kernel?  I can only find patches to 2.4.18.  I see LSM has a patch to 2.4.19
but I read somewhere that I should only use SELinux LSM patches.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2014-01-10 14:44 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-01-10  9:16 new to selinux Bryan Harris
2014-01-10  9:33 ` Ilya Frolov
2014-01-10 13:47   ` Daniel J Walsh
2014-01-10 14:44 ` Stephen Smalley
  -- strict thread matches above, loose matches on Subject: below --
2005-08-10 15:48 nitin kanaskar
2005-08-10 16:46 ` Stephen Smalley
2002-08-22 19:03 New to SELinux M. H.
2002-08-19 21:26 Westerman, Mark
2002-08-20 11:37 ` Stephen Smalley
2002-08-19 20:33 Jeremy Kusnetz
2002-08-19 20:47 ` Russell Coker
2002-08-20 10:51 ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.