|
Research
Skip Research Menus
Research MenuSecurity Enhanced Linux What's New Frequently Asked Questions Background Documents License Download Participating Mail List Archives Remaining Work Contributors Related Work Press Releases Information Assurance Research NIARL In-house Research Areas Mathematical Sciences Program Sabbaticals Computer & Information Sciences Research Technology Transfer Advanced Computing Advanced Mathematics Communications & Networking Information Processing Microelectronics Other Technologies Technology Fact Sheets Publications Related Links |
SELinux Mailing ListRe: use of ps in ipsec shutdown
From: Paul Krumviede <pwk_at_acm.org>
Date: Mon, 03 Dec 2001 07:40:53 -0800
> what i want to do is partition all of the ipsec-related code, and then break those things into more specific domains, such as a domain that can access/manage keying material and a domain that can access things in the first domain (perhaps an ipsec_client_t as you suggest in a subsequent messages). i've been thinking of an ipsec_admin role as well (one of mark's comments in sysadm.te alludes to this) and then restricing access to some of the ipsec functions to this role (and to initrc_t). the first pass at such a partition started when i noticed that i had processes running in the initrc_t domain.
>> i also noticed that _startklips wanted (limited) access that seems worthwhile.
>> i later noticed a number of avc denials at shutdown yes, for some reason i was thinking that ps would fail. i'll add the auditdeny rules.
>> i'd be happy to share the changed/new policy files when i i'll work on refining what i have to reflect a division between things that actually need to access the PF_KEY socket and those things that don't need direct access to the socket. -paul -- You have received this message because you are subscribed to the selinux list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.Received on Mon 3 Dec 2001 - 10:54:59 EST |
|
|
Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009 |












