All of lore.kernel.org
 help / color / mirror / Atom feed
* semanage interface has no effect
@ 2014-08-25 11:11 Stepan G. Fedorov
  2014-08-25 12:18 ` Dominick Grift
  2014-08-25 13:10 ` Stephen Smalley
  0 siblings, 2 replies; 10+ messages in thread
From: Stepan G. Fedorov @ 2014-08-25 11:11 UTC (permalink / raw)
  To: Selinux

Hello!

Goal of this experiment is to see allow rules for netif class objects is 
working.

I use debian wheezy whith MLS selinux policy, in enforced mode.

eth0 is hte only netwotk interface, except lo.

sesearch --allow -cnetif shows lots of allow rules for netif_t target 
type / netif target class.

I do:
  1) I add new type nginx_http_if_t with my own policy module;
  2) semanage interface -a -t nginx_http_if_t -r s1:c0.c1023 eth0.

I expect: to see all the processes in system unable to read/write 
packets from eth0 interface.

I actually got: nothing changes - all networking is working as it was 
before changing of interface context.


What am I doing/understanding wrong?

Thank you!

-- 
Stepan G. Fedorov <StFedorov@gmail.com>
Tel: +7-965-750-91-91

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2014-08-25 15:46 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-08-25 11:11 semanage interface has no effect Stepan G. Fedorov
2014-08-25 12:18 ` Dominick Grift
2014-08-25 13:10 ` Stephen Smalley
2014-08-25 14:00   ` Stepan G. Fedorov
2014-08-25 14:30     ` Paul Moore
2014-08-25 14:36       ` Stephen Smalley
2014-08-25 14:57         ` Stepan G. Fedorov
2014-08-25 15:46           ` Christopher J. PeBenito
2014-08-25 14:46       ` Stepan G. Fedorov
2014-08-25 15:21         ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.