Research Menu

.
Skip Search Box

SELinux Mailing List

Re: Patch to add a "netuser" role and user

From: Christopher J. PeBenito <cpebenito_at_tresys.com>
Date: Wed, 08 Mar 2006 13:30:11 -0500


On Wed, 2006-03-08 at 00:13 +0100, Erich Schubert wrote:
> Hi,
> the following patch adds a "netuser" user and role.
> This is pretty much the same to user_u/user_r/user_t
> except that these users can bind non-privileged tcp ports
> (like user_u with the user_tcp_server boolean, no ssh port forwarding
> though)
>
> Maybe this patch (when reviewed) could serve as an example on how to add
> new user roles?

The patch is a reasonable example for adding roles, but I'm not sure that it should be added. I can't think of a compelling need for it, especially since its basically user_r with user_tcp_server enabled, as you mention above.

-- 
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Wed 8 Mar 2006 - 13:30:51 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service