Research
.
Skip Search Box

SELinux Mailing List

Re: [idea] multiple contexts.

From: Luke Kenneth Casson Leighton <lkcl_at_lkcl.net>
Date: Tue, 27 Jul 2004 22:49:11 +0100


On Tue, Jul 27, 2004 at 05:23:38PM -0400, Valdis.Kletnieks@vt.edu wrote:
> On Tue, 27 Jul 2004 22:28:36 BST, Luke Kenneth Casson Leighton said:
>
> > yes, sort-of: more that i only wish to limit what programs a user
> > can run (and what programs _those_ programs can run).
> >
> > in particular, i want to stop people from being able to use the
> > "Run" capability of Konqueror, etc. STOP, not have the popup coming
> > up with "are you sure you want to run this program?".
>
> Do these users have anything resembling shell access? If they can get an xterm
> or an editor open, they can run the program *anyhow*....
 

 no, xterm will not be on the list of programs they can run :)

 when i say it'll be a list of programs that they can run i MEAN  if it ain't on the list it ain't gonna run.

 i.e. it's mandatory access control,

> Probably easier to do the kdeuser group and start chgrp'ing, than to try to fight THAT
> war.
>
> Or see how hard it would be to create a patch to Konqueror to disable the
> button, and see if you can push it upstream...

 there are more places, there are more programs.

 other programs, such as ksmoothdock, such as Basket, such as kxdocker,  such as KMenu being edited and people manually putting programs onto  their menus.

 all of these things i just don't wanna know about _how_ they are run:  if they ain't on the list, splat.

 make a user a member of kdeusers + chgrp-to-kdeusers + 0660 on all  exes in the "allowed list" is my "fallback" position.

 i'd just rather it wasn't the only position.

 l.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Tue 27 Jul 2004 - 17:38:13 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service