Research
.
Skip Search Box

SELinux Mailing List

Re: Proposed patch to policy file_contexts

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Mon, 08 Mar 2004 12:33:25 -0500


On Mon, 2004-03-08 at 10:59, Karl MacMillan wrote:
> Our thinking was that root shouldn't be a special case and the ordering
> of the roles could take care of everything. I'm not clear why root
> should be labeled with sysadm*_home_t, though. Why not treat root like
> all of the other admins? Wouldn't labeling root with sysadm*_home_t make
> logging in as staff_r for root problematic (for example, when ssh logins
> are allowed for root).

Yes, it makes life a little harder for direct remote root logins (but doesn't prevent them from occurring; you just have to do a subsequent newrole to get to a full normal operating state). But it also protects the integrity of /root's dotfiles more strongly, which can be helpful.

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Mon 8 Mar 2004 - 12:34:02 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service