Security Enhanced Linux
What's New
Frequently Asked Questions
Background
Documents
License
Download
Participating
Mail List
Archives
Remaining Work
Contributors
Related Work
Press Releases
Information Assurance Research
NIARL In-house Research Areas
Mathematical Sciences Program
Sabbaticals
Computer & Information Sciences Research
Technology Transfer
Advanced Computing
Advanced Mathematics
Communications & Networking
Information Processing
Microelectronics
Other Technologies
Technology Fact Sheets
Publications
Related Links
|
SELinux Mailing ListRe: Policy questions
From: Brian May <bam_at_snoopy.apana.org.au>
Date: Sat, 27 Jul 2002 13:31:53 +1000
Is the problem here that you are trying to relabel system_u to rjc?
> So if I made setfiles have special-case code for /home which searches for an Personally, I don't like the idea of relabel touching the home directory. It seems to have some limitations:
Some ideas: Maybe have some sort of script that the user runs to initially setup the initial directories and labels for a given program (eg. user runs "setup netscape"). This script may need special relabel priviledges, if the user doesn't already have them. Have adduser automatically label files for new users using the new SE-Linux user it just created (hmmm... generic hooks into adduser might be ideal here). When initially installing selinux set all home directories the "best" defaults using some sort of hacked script, and tell system adminstrator to check that this is correct. Allow users to relabel there files to/from public_html, depending on local policy. Otherwise prevent users from renaming the ~/public_html directory (is this possible?). -- Brian May <bam@snoopy.apana.org.au> -- You have received this message because you are subscribed to the selinux list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.Received on Fri 26 Jul 2002 - 23:54:14 EDT |
|
Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009 |