All of lore.kernel.org
 help / color / mirror / Atom feed
* Labelling problems with a user directly running an application in a confined domain
@ 2014-04-01 13:59 Kim Lawson-Jenkins
  2014-04-01 15:12 ` Stephen Smalley
  0 siblings, 1 reply; 7+ messages in thread
From: Kim Lawson-Jenkins @ 2014-04-01 13:59 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 754 bytes --]

Hi,

 

I'm pretty sure my questions are basic SELinux 101 but I'm having a problem
confining an application when a user runs the application directly.  On our
system I have removed the unconfined domain and unconfined user.  When the
system initializes the confined applications run in the correct confined
domains.  However, if I use ssh to access the server, stop an application,
and then start the application again, the application will run with the
label sshd_t.  I haven't tried starting a confined application from a local
console but I'll probably encounter a similar problem.  How should I modify
the policy to allow a confined user to execute an application but  also have
the application run in the application's confined domain?

 

Kim

 


[-- Attachment #2: Type: text/html, Size: 2529 bytes --]

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2014-04-01 18:08 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-04-01 13:59 Labelling problems with a user directly running an application in a confined domain Kim Lawson-Jenkins
2014-04-01 15:12 ` Stephen Smalley
2014-04-01 17:04   ` Kim Lawson-Jenkins
2014-04-01 17:07     ` Stephen Smalley
2014-04-01 17:42       ` Kim Lawson-Jenkins
2014-04-01 17:53         ` Stephen Smalley
2014-04-01 18:08           ` Kim Lawson-Jenkins

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.