Re: SELinux survey (was RE: Stupid F7 boot loop)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Les Mikesell wrote:
Rahul Sundaram wrote:


http://www.redhatmagazine.com/2007/05/04/whats-new-in-selinux-for-red-hat-enterprise-linux-5/


This article doesn't explain whether it follows standards or will always be a single-supplier non-standard extension.

That's not the focus of the article. There are other documentation available for what you want to know.

What standard are you talking about? There is no single supplier nor is this a non-standard extension. SELinux is merged upstream and uses extended attributions (xattr) which is not SELinux specific.

Multiple distributions and operating systems support the same mechanisms. See http://selinux.sourceforge.net/ and http://www.trustedbsd.org/sebsd.html for some details.

All distributions that ship policy today are based on the reference policy mechanism with customizations to enable them work with differences in distributions or can be tweaked to enforce different security restrictions (strict vs targeted or something else)

  If you are using SELinux,
can you still transparently replace your local disks with network mounts where the systems hosting the disks are appliances or running some other OS?

You can. Most of the software don't require any SELinux specify modifications and a central policy will be applied on them. Filesystems that don't read the extended attributes will ignore it (an example of this is NFS. I believe all others .You can assign a specific context via the mount command over a entire mount if the filesystem does not support extended attributes. More details on the mount man page.

 If you can't do that today, is the standard published to
permit it eventually?

You can find examples on how to add extended attribute support by looking at the existing software if that is what you are asking for.

Rahul

--
fedora-list mailing list
fedora-list@xxxxxxxxxx
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list
[Index of Archives]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [Fedora Magazine]     [Fedora News]     [Fedora Summer Coding]     [Fedora Laptop]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Maintainers]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Legacy]     [Fedora Desktop]     [Fedora Fonts]     [ATA RAID]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [SSH]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Centos]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Tux]     [Yosemite News]     [Gnome Users]     [KDE Users]     [Fedora Art]     [Fedora Docs]     [Asterisk PBX]     [Fedora Sparc]     [Fedora Universal Network Connector]     [Libvirt Users]     [Fedora ARM]

  Powered by Linux