All of lore.kernel.org
 help / color / mirror / Atom feed
From: Daniel J Walsh <dwalsh@redhat.com>
To: Andrew Ruch <adruch2002@gmail.com>, SELinux ML <selinux@tycho.nsa.gov>
Subject: Re: Diskless system running SELinux
Date: Thu, 7 Jan 2016 17:21:26 -0500	[thread overview]
Message-ID: <568EE4E6.6090907@redhat.com> (raw)
In-Reply-To: <CAPubmWXt3Ds7T5V8rYBZKhLQKLymw7_un+d-eN-0_CwxU3BmMA@mail.gmail.com>



On 01/07/2016 04:48 PM, Andrew Ruch wrote:
> Hello,
>
> I'm researching deploying a diskless system that would use PXEBoot and
> NFS for it's storage. I believe this capability has been proven and
> have no issues here. The tricky part is this system must also have
> Mandatory Access Control. I thought RHEL 7.2 was the answer due to
> it's support of labeled NFS. However, Red Hat just told me that having
> an SELinux-labeled, remote root partition is unsupported. What wasn't
> clear was if the problem was in RHEL or something upstream.
>
> Does the kernel support a labeled, remote root partition? If so, which
> distributions support this?
>
>
> Thanks,
> Andrew Ruch
> _______________________________________________
> Selinux mailing list
> Selinux@tycho.nsa.gov
> To unsubscribe, send email to Selinux-leave@tycho.nsa.gov.
> To get help, send an email containing "help" to Selinux-request@tycho.nsa.gov.
>
>
I just think no one has ever tried this.  If the remote system is setup
with nfs labeling, theoretically this
should work.

Not only rhel7 supports labeled networking on the server and client, to
the best of my knowleged.

Not sure if NetApp or EMC support it yet.

  reply	other threads:[~2016-01-07 22:22 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-01-07 21:48 Diskless system running SELinux Andrew Ruch
2016-01-07 22:21 ` Daniel J Walsh [this message]
2016-01-07 22:38   ` Andrew Ruch
2016-01-08 18:44     ` Daniel J Walsh
2016-11-12  2:35 ` Russell Coker

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=568EE4E6.6090907@redhat.com \
    --to=dwalsh@redhat.com \
    --cc=adruch2002@gmail.com \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.