Research Menu

.
Skip Search Box

SELinux Mailing List

can_ypbind()

From: Russell Coker <russell_at_coker.com.au>
Date: Tue, 9 Mar 2004 23:46:29 +1100


It seems that on a NIS system most domains need access to it. So it seems reasonable to put a call to can_ypbind() in daemon_domain() to cover most daemons. I considered daemon_base_domain() or daemon_core_rules() but that makes it too awkward to implement a basic daemon that has no network access on a NIS system.

Also it seems that anything which needs NIS access will also need NSCD or LDAP access depending on the configuration of the system. So maybe instead of can_ypbind() we should have can_account_lookup() (or some better name) which will then permit NIS, NIS+, LDAP, NSCD, or whatever else is necessary to do the job.

What do you think?

--

http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/  My home page

--

This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message. Received on Tue 9 Mar 2004 - 07:48:22 EST

 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service