Research Menu

.
Skip Search Box

SELinux Mailing List

Re: Current Reference Policy patch

From: Christopher J. PeBenito <cpebenito_at_tresys.com>
Date: Thu, 17 Nov 2005 14:02:44 -0500


On Thu, 2005-11-17 at 10:55 -0500, Daniel J Walsh wrote:
> Need to turn on rpm and not alias to unconfined_t, because the rule
>
> rpm_t->shell_exec_t->rpm_script_t was causing all terminal windows to
> run in rpm_script_t in targeted.

Yesterday I disabled that transition in targeted (it was the one causing the xdm logins to go to rpm_script_t), so do you still want to rpm_t as non-aliased?

> Allow users to su to root and then suspend the session.
>
> Pegasus policy was too loose.
> /bin/ksh should be sheel_exec_t
> (.*)? is the same as .* and causes python to blow up.
>

-- 
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Thu 17 Nov 2005 - 14:10:25 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service