Research Menu

.
Skip Search Box

SELinux Mailing List

Re: xen 2.0 - adding selinux permissions

From: Luke Kenneth Casson Leighton <lkcl_at_lkcl.net>
Date: Wed, 24 Nov 2004 20:19:50 +0000


On Wed, Nov 24, 2004 at 01:13:15PM -0500, Colin Walters wrote:
> On Wed, 2004-11-24 at 15:49 +0000, Luke Kenneth Casson Leighton wrote:
>
> > okay, regarding the second argument to avc_has_perm(),
> > i asked the nice xen developers if it'd be possible to
> > associate a sid with each virtual machine.
>
> When would you want a process to be able to control one Xen machine but
> not another?
 

 i described such a scenario in an earlier message today to stephen:  giving an operator-admin the right to reboot a VM running a SQL server  but NOT giving that same operator the right to reboot the master OS  which, if you rebooted that, would take down every single VM with it.

 l.

-- 
--
<a href="http://lkcl.net">http://lkcl.net</a>
--

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Wed 24 Nov 2004 - 15:09:22 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service