Research
.
Skip Search Box

SELinux Mailing List

Re: can_network patch.

From: Daniel J Walsh <dwalsh_at_redhat.com>
Date: Fri, 26 Nov 2004 06:55:52 -0500


Russell Coker wrote:

>On Wednesday 24 November 2004 07:07, Stephen Smalley <sds@epoch.ncsc.mil>
>wrote:
>
>
>>If no one agrees with me about preserving can_network() semantics, then
>>I can be overruled. But I thought that Russell had voiced a similar
>>concern earlier.
>>
>>
>
>I still think that can_network() should keep it's traditional functionality.
>
>
>

The latest patch can_network has the same functionality, we now have other options to tighten security though.

can_network_tcp
can_network_udp
...

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Fri 26 Nov 2004 - 06:56:23 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service