All of lore.kernel.org
 help / color / mirror / Atom feed
From: bsniffen@mitre.org (Brian T. Sniffen)
To: SELinux <SELinux@tycho.nsa.gov>
Subject: Re: Question about integration of IPsec with SELinux?
Date: Thu, 16 Jun 2005 12:01:41 -0400	[thread overview]
Message-ID: <d287jguwasa.fsf@jon-strange.mitre.org> (raw)
In-Reply-To: <20050613220328.31770.qmail@web31602.mail.mud.yahoo.com> (Casey Schaufler's message of "Mon, 13 Jun 2005 15:03:28 -0700 (PDT)")

Casey Schaufler <casey@schaufler-ca.com> writes:

> Username mapping errors are bad, but one or the
> other of the individuals involved usually detects
> the problem quickly enough. I don't know that I'd
> expect the same to be true of policy elements.

We already see admins doing this regularly: they drop a file from Red
Hat's strict policy into the their Fedora system using Targeted
policy, or from Fedora onto a Debian system, and are surprised when it
does not work.

The average userbase will always expect user_t and httpd_t to mean the
same things everywhere, even though they will not.  It's because of
this difficulty that polgen does only structural analysis, ignoring
accidents of naming.  We're having enough trouble adapting our output
to the evolving details of policy differences (e.g., unconfined_t vs. user_t).

-Brian


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  parent reply	other threads:[~2005-06-16 16:10 UTC|newest]

Thread overview: 42+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <20050613213951.GB17617@lkcl.net>
2005-06-13 22:03 ` Question about integration of IPsec with SELinux? Casey Schaufler
2005-06-13 22:44   ` Luke Kenneth Casson Leighton
2005-06-16 16:01   ` Brian T. Sniffen [this message]
2005-06-14 18:11 Park Lee
2005-06-14 21:23 ` Casey Schaufler
2005-06-15  1:20   ` Park Lee
2005-06-15  3:00     ` Casey Schaufler
  -- strict thread matches above, loose matches on Subject: below --
2005-06-11 10:38 Park Lee
2005-06-11 17:27 ` Casey Schaufler
2005-06-11 18:45   ` Park Lee
2005-06-11 19:18     ` Valdis.Kletnieks
2005-06-11 19:49       ` Casey Schaufler
2005-06-12  2:16         ` Park Lee
2005-06-12 11:44           ` Luke Kenneth Casson Leighton
2005-06-12 12:39             ` Valdis.Kletnieks
2005-06-12 15:20               ` Luke Kenneth Casson Leighton
2005-06-12 19:18                 ` Valdis.Kletnieks
2005-06-12 20:25                   ` Luke Kenneth Casson Leighton
2005-06-12 20:30                     ` Valdis.Kletnieks
2005-06-12 20:52                     ` Luke Kenneth Casson Leighton
2005-06-12 21:45                       ` Valdis.Kletnieks
2005-06-13 13:00                     ` Stephen Smalley
2005-06-13 21:16                       ` Luke Kenneth Casson Leighton
2005-06-14 13:21                         ` Stephen Smalley
2005-06-14 14:31                           ` Trent Jaeger
2005-06-15 22:04                             ` Luke Kenneth Casson Leighton
2005-06-12 23:32                   ` Casey Schaufler
2005-06-13  0:21                     ` Valdis.Kletnieks
2005-06-13 10:01                     ` Luke Kenneth Casson Leighton
2005-06-13 13:37                       ` Valdis.Kletnieks
2005-06-13 14:10                       ` Casey Schaufler
2005-06-13 12:49                 ` Stephen Smalley
2005-06-13 21:17                   ` Luke Kenneth Casson Leighton
2005-06-13 12:37             ` Stephen Smalley
2005-06-13 21:19               ` Luke Kenneth Casson Leighton
2005-06-12 12:34           ` Valdis.Kletnieks
2005-06-12 15:25             ` Luke Kenneth Casson Leighton
2005-06-12 16:16             ` Park Lee
2005-06-12 17:50           ` Casey Schaufler
2005-06-12 16:34   ` Park Lee
2005-06-12 17:02   ` Park Lee
2005-06-12 17:46     ` Casey Schaufler

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=d287jguwasa.fsf@jon-strange.mitre.org \
    --to=bsniffen@mitre.org \
    --cc=SELinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.