From: Stephen Smalley <sds@tycho.nsa.gov>
To: dE <de.techno@gmail.com>, selinux@tycho.nsa.gov
Subject: Re: RBAC along with MLS?
Date: Mon, 09 Jun 2014 09:28:13 -0400 [thread overview]
Message-ID: <5395B66D.5010909@tycho.nsa.gov> (raw)
In-Reply-To: <5391B555.4080100@gmail.com>
On 06/06/2014 08:34 AM, dE wrote:
> I'm learning SELinux on Fedora, here if you need to use MLS, you need to
> remove TE model cause the MLS is implemented in a completely different
> policy.
>
> Is it possible to create a policy which supports both RABC/TE with MLS?
I've explained this previously, but to repeat it: RBAC/TE is always
enabled in the SELinux security server (and in the policy), only MLS is
optional. So in Fedora, the -mls policy is in truth a RBAC/TE/MLS
policy. And in Fedora, the -targeted policy is in truth a RBAC/TE/MCS
policy. They both enable the MLS engine in the security server; they
only differ in the configuration (policy/mls versus policy/mcs).
prev parent reply other threads:[~2014-06-09 13:28 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-06-06 12:34 RBAC along with MLS? dE
2014-06-09 13:28 ` Stephen Smalley [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5395B66D.5010909@tycho.nsa.gov \
--to=sds@tycho.nsa.gov \
--cc=de.techno@gmail.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.