From mboxrd@z Thu Jan 1 00:00:00 1970 Message-ID: <55847E54.1010802@redhat.com> Date: Fri, 19 Jun 2015 16:40:52 -0400 From: Daniel J Walsh Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="=_Boundary-9904-1434746685-0001-2" To: Andrew Holway , James Carter Subject: Re: NFS References: <55846D8E.5010904@tycho.nsa.gov> In-Reply-To: Cc: "selinux@tycho.nsa.gov" List-Id: "Security-Enhanced Linux \(SELinux\) mailing list" List-Post: List-Help: This is a MIME-formatted message. If you see this text it means that your E-mail software does not support MIME-formatted messages. --=_Boundary-9904-1434746685-0001-2 Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: quoted-printable X-Mime-Autoconverted: from 8bit to quoted-printable by mime827 On 06/19/2015 04:19 PM, Andrew Holway wrote: > > > The v3 work was experimental and there was no real way to upstream > it in a compatible way. > > Dave Quigley worked with the IETF on SELinux labeled NFS support > for NFS 4.2 and it has been available since Fedora 20. This allows > each file to have their own SELinux label on the server, but > enforcement is only handled by the client. > > > Does it work? :) > Yes as long as your client and server support the protocol. Currently I know Fedora and RHEL7 do. > > > > -- > James Carter > National Security Agency > _______________________________________________ > Selinux mailing list > Selinux@tycho.nsa.gov > To unsubscribe, send email to Selinux-leave@tycho.nsa.gov. > To get help, send an email containing "help" to > Selinux-request@tycho.nsa.gov. > > > > -- > Otter Networks UG > http://otternetworks.de > fon: +49 30 54 88 5197 > Gotenstra=DFe 17 > 10829 Berlin > > > > _______________________________________________ > Selinux mailing list > Selinux@tycho.nsa.gov > To unsubscribe, send email to Selinux-leave@tycho.nsa.gov. > To get help, send an email containing "help" to Selinux-request@tycho.= nsa.gov. --=_Boundary-9904-1434746685-0001-2 Content-Type: text/html; charset=windows-1252 Content-Transfer-Encoding: quoted-printable X-Mime-Autoconverted: from 8bit to quoted-printable by mime827

On 06/19/2015 04:19 PM, Andrew Holway wrote:

The v3 work was experimental and there was no real way to upstream it in a compatible way.

Dave Quigley worked with the IETF on SELinux labeled NFS support for NFS 4.2 and it has been available since Fedora 20. This allows each file to have their own SELinux label on the server, but enforcement is only handled by the client.

=A0
Does it work? :)

Yes as long as your client and server support the protocol.=A0 Currently I know Fedora and RHEL7 do.
=A0

--
James Carter <jwcart2@tycho.nsa.g= ov>
National Security Agency
_______________________________________________
Selinux mailing list
Selinux@tycho.nsa.gov
To unsubscribe, send email to Selinu= x-leave@tycho.nsa.gov.
To get help, send an email containing "help" to Selinux-request@tycho.nsa.gov.


--
Otter Networks UG
http://otternetworks.de
fon: +49 30 54 88 5197
Gotenstra=DFe 17
10829 Berlin



_______________________________________________
Selinux mailing list
Selinux@tycho.nsa.gov
To unsubscribe, send email to Selinux-leave@tycho.nsa.gov.
To get help, send an email containing "help" to Selinux-requ=
est@tycho.nsa.gov.

--=_Boundary-9904-1434746685-0001-2--