Research
.
Skip Search Box

SELinux Mailing List

Re: MCS and unconfined_t

From: Stephen Smalley <sds_at_tycho.nsa.gov>
Date: Wed, 29 Mar 2006 07:35:44 -0500


On Wed, 2006-03-29 at 11:36 +1100, Russell Coker wrote:
> The problem we have is that we want su(1) to allow changing to the SE Linux
> context of the new user with the appropriate MCS categories. To do this we
> need to have su run in it's own domain so that it is permitted to increase
> the categories while the unconfined_t domain isn't. I plan to release this
> as an FC5 update.
>
> For the moment KaiGai Kohei is correct and there is no way to effectively
> constrain unconfined_t.

Hmm...but su no longer uses pam_selinux, so it isn't supposed to change SELinux context (aside from automatic transitions).

-- 
Stephen Smalley
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Wed 29 Mar 2006 - 07:31:06 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service