Research
.
Skip Search Box

SELinux Mailing List

Re: Proposed patch to policy file_contexts

From: Russell Coker <russell_at_coker.com.au>
Date: Tue, 9 Mar 2004 03:05:40 +1100


On Tue, 9 Mar 2004 02:59, Karl MacMillan <kmacmillan@tresys.com> wrote:
> > The resulting file_contexts file maps /root entries to staff*_home_t
> > rather than sysadm*_home_t. This is a general limitation of
> > genhomedircon (not knowing which role to select when multiple ones are
> > authorized), but the old one avoided the problem by skipping root and
> > leaving the /root entries in the .fc files. Now, we could alter the
> > ordering of roles for root in policy/users as a workaround; that
> > shouldn't affect the default context as that is governed by
> > /etc/security/default_contexts.
>
> Our thinking was that root shouldn't be a special case and the ordering
> of the roles could take care of everything. I'm not clear why root
> should be labeled with sysadm*_home_t, though. Why not treat root like
> all of the other admins? Wouldn't labeling root with sysadm*_home_t make
> logging in as staff_r for root problematic (for example, when ssh logins
> are allowed for root).

Why not allow staff_t to search sysadm_home_dir_t:dir and read sysadm_home_t:file? Then you can login as root:staff_r and still get aliases etc setup, and then you can run "newrole -r sysadm_r".

I've got policy to do that in my tree already.

-- 
http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/  My home page

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Mon 8 Mar 2004 - 11:07:14 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service