Research Menu

.
Skip Search Box

SELinux Mailing List

Re: how to test ssh_sysadm_login(tunable)

From: Jian Liu <gjk.liu_at_gmail.com>
Date: Sun, 3 Dec 2006 17:14:33 +0800


On 12/1/06, Russell Coker <russell@coker.com.au> wrote:
>
> On Friday 01 December 2006 20:33, "Jian Liu" <gjk.liu@gmail.com> wrote:
> > In refpolicy, there is a global tunable named "ssh_sysadm_login". It
> means
> > "Allow ssh logns as sysamd_r:sysadm_t".
> > How to use this tunable?
> >
> > I have tested it on my lab, and find It is always allowed to "newrole -r
> > sysadm_r -t sysadm_t" after sshed
> > to my test server, not mattering ssh_sysadm_login is on or off on the
> > server.
>
> That is the way it's designed.
>
> The boolean in question determines whether you are permitted to ssh
> directly
> as sysadm_t, not whether you can run newrole after that.
>

But, after "ssh_sysadm_login" is set to on, there is not a login menu containing
"sysadm_r:sysadm_t". Moreover, when I use ssh , there is no any scontext select
menu as local login.

 by Liu Jian



email to: GJK.Liu@gmail.com
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Sun 3 Dec 2006 - 04:14:12 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service