Research
.
Skip Search Box

SELinux Mailing List

Re: changes in ~2.6.13 break postfix policy?

From: James Morris <jmorris_at_namei.org>
Date: Tue, 15 Nov 2005 08:58:14 -0500 (EST)


On Tue, 15 Nov 2005, Stephen Smalley wrote:

> True. However, I can envision people who want to apply SELinux for
> local confinement of processes without necessarily caring about the
> network controls, and I can further envision them not wanting the
> performance overhead on the network path created by e.g. the
> sock_rcv_skb hook and the netfilter hooks. So that seems like a
> reasonable configuration option. The current CONFIG_SECURITY_NETWORK
> isn't very useful in that respect because it covers not only those
> networking checks but also the socket hooks, including the checking for
> Unix/local sockets.

Well, we could add an SELinux-only config option for local confinement if someone asks for it.

  • James -- James Morris <jmorris@namei.org>
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Tue 15 Nov 2005 - 09:05:38 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service