Research Menu

.
Skip Search Box

SELinux Mailing List

Re: init patch for loading policy

From: Daniel J Walsh <dwalsh_at_redhat.com>
Date: Tue, 21 Oct 2003 13:50:56 -0400


Stephen Smalley wrote:

>On Tue, 2003-10-21 at 10:43, Russell Coker wrote:
>
>
>>The results I have so far indicate that this approach has significant
>>problems.
>>
>>Diverting /sbin/init with a shell script works better than this.
>>
>>
>
>Ok, thanks for looking into it. So what exactly is the problem with
>diverting /sbin/init again?
>
>
>

I still believe that the patch to /sbin/init is simple enough that all the rest of this stuff is complicating matters. It allows too many ways for someone to make a modification that breaks security. I have updated the files on people.redhat.com/dwalsh to use the modified init. I have passed this by Bill Nottingham (Red Hat maintainer) and he is ok with it.

Of course if someone comes up with a simpler solution we would look at it.

Dan

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Tue 21 Oct 2003 - 13:51:07 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service