Research Menu

.
Skip Search Box

SELinux Mailing List

Re: Patch to add a "netuser" role and user

From: Christopher J. PeBenito <cpebenito_at_tresys.com>
Date: Thu, 09 Mar 2006 09:46:57 -0500


On Wed, 2006-03-08 at 20:13 +0100, Erich Schubert wrote:
> > The patch is a reasonable example for adding roles, but I'm not sure
> > that it should be added. I can't think of a compelling need for it,
> > especially since its basically user_r with user_tcp_server enabled, as
> > you mention above.
>
> Except that you might not want to allow user_tcp_server for all users,
> and with netuser you can give this permission easily to individual users
> on a per-user basis.

That is true, but I don't find binding to generic ports to be a compelling reason to add another role to the upstream policy.

-- 
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Thu 9 Mar 2006 - 09:47:29 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service