All of lore.kernel.org
 help / color / mirror / Atom feed
From: Daniel J Walsh <dwalsh@redhat.com>
To: Andrew Ruch <adruch2002@gmail.com>
Cc: SELinux ML <selinux@tycho.nsa.gov>
Subject: Re: Diskless system running SELinux
Date: Fri, 8 Jan 2016 13:44:48 -0500	[thread overview]
Message-ID: <569003A0.4020605@redhat.com> (raw)
In-Reply-To: <CAPubmWXD0Oro89LEZ+UAqA=DkdJ7myzSuA_vspeCrd7cdwg+4g@mail.gmail.com>



On 01/07/2016 05:38 PM, Andrew Ruch wrote:
> On Thu, Jan 7, 2016 at 3:21 PM, Daniel J Walsh <dwalsh@redhat.com> wrote:
>>
>> On 01/07/2016 04:48 PM, Andrew Ruch wrote:
>>> Hello,
>>>
>>> I'm researching deploying a diskless system that would use PXEBoot and
>>> NFS for it's storage. I believe this capability has been proven and
>>> have no issues here. The tricky part is this system must also have
>>> Mandatory Access Control. I thought RHEL 7.2 was the answer due to
>>> it's support of labeled NFS. However, Red Hat just told me that having
>>> an SELinux-labeled, remote root partition is unsupported. What wasn't
>>> clear was if the problem was in RHEL or something upstream.
>>>
>>> Does the kernel support a labeled, remote root partition? If so, which
>>> distributions support this?
>>>
>>>
>>> Thanks,
>>> Andrew Ruch
>>> _______________________________________________
>>> Selinux mailing list
>>> Selinux@tycho.nsa.gov
>>> To unsubscribe, send email to Selinux-leave@tycho.nsa.gov.
>>> To get help, send an email containing "help" to Selinux-request@tycho.nsa.gov.
>>>
>>>
>> I just think no one has ever tried this.  If the remote system is setup
>> with nfs labeling, theoretically this
>> should work.
>>
>> Not only rhel7 supports labeled networking on the server and client, to
>> the best of my knowleged.
>>
>> Not sure if NetApp or EMC support it yet.
> Hmmm...  Red Hat Support referred me to an installation guide [1] at
> the very bottom of section 2.2. It says that SELinux must be disabled
> for diskless clients that use NFS as the root file system. I'm not
> trying to use RHEL for Real Time so I'll do some experimenting to see
> what I can figure out.
>
> Thanks,
> Andrew
>
>
> [1] https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux_for_Real_Time/7/html/Installation_Guide/Installing_Real_Time_Using_Diskless_Boot.html
> _______________________________________________
> Selinux mailing list
> Selinux@tycho.nsa.gov
> To unsubscribe, send email to Selinux-leave@tycho.nsa.gov.
> To get help, send an email containing "help" to Selinux-request@tycho.nsa.gov.
>
>
Right, because in most cases NFS will not support labels.  This probably
should be changed to say it is not supported unless you set up labeled
networking on client /server (And it actually works.)  If you prove that
it can work, I can work to get the Support changed.

  reply	other threads:[~2016-01-08 18:45 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-01-07 21:48 Diskless system running SELinux Andrew Ruch
2016-01-07 22:21 ` Daniel J Walsh
2016-01-07 22:38   ` Andrew Ruch
2016-01-08 18:44     ` Daniel J Walsh [this message]
2016-11-12  2:35 ` Russell Coker

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=569003A0.4020605@redhat.com \
    --to=dwalsh@redhat.com \
    --cc=adruch2002@gmail.com \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.