Research
.
Skip Search Box

SELinux Mailing List

Re: SELinux capable UML's (bonus: root_fs creation on Debian)

From: Colin Walters <walters_at_verbum.org>
Date: Wed, 03 Nov 2004 15:18:46 -0500


On Wed, 2004-11-03 at 11:16 -0600, Manoj Srivastava wrote:

> 	I hope this document shall be useful. I find that this is

> useful for running services on an otherwise insecure box, since in a
> number of real world situations, a machine can not be run in
> enforcing mode, possibly because it needs to run applications and
> services for which MAC policy has not yet been written.

There is the approach of simply marking the programs as unconfined_exec_t until policy is written.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Wed 3 Nov 2004 - 15:18:50 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service