From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1IC3yV-0003dQ-OX for qemu-devel@nongnu.org; Fri, 20 Jul 2007 21:41:39 -0400 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1IC3yU-0003cZ-VR for qemu-devel@nongnu.org; Fri, 20 Jul 2007 21:41:39 -0400 Received: from [199.232.76.173] (helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1IC3yU-0003cU-Qg for qemu-devel@nongnu.org; Fri, 20 Jul 2007 21:41:38 -0400 Received: from mail2.sea5.speakeasy.net ([69.17.117.4]) by monty-python.gnu.org with esmtps (TLS-1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.60) (envelope-from ) id 1IC3yU-0003xP-BN for qemu-devel@nongnu.org; Fri, 20 Jul 2007 21:41:38 -0400 Date: Fri, 20 Jul 2007 21:41:31 -0400 (EDT) From: James Morris In-Reply-To: <20070720235007.GA1595@redhat.com> Message-ID: References: <20070720201101.GC12218@redhat.com> <25a1d91b0707201457m6865a505maf93d22c5c28f0cc@mail.gmail.com> <20070720235007.GA1595@redhat.com> MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Subject: [Qemu-devel] Re: [kvm-devel] [RFC][PATCH 00/01]qemu VM entrypoints Reply-To: qemu-devel@nongnu.org List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: "Daniel P. Berrange" Cc: David Windsor , kvm-devel , qemu-devel , selinux , Joshua Brindle , David Windsor On Sat, 21 Jul 2007, Daniel P. Berrange wrote: > obviously the UNIX user has a corresponding SELinux domain. In the remote > case, one could map x509 certificate IDs (the remote user's identify) to > appropriate local SELinux domains. There is already a mechanism for conveying SELinux labels over the network via IPsec. - James -- James Morris