On Thu, 2004-03-11 at 10:36, Stephen Smalley wrote: > Even > then, you still need to start from staff_r in order to reach sysadm_r; > the policy doesn't allow user_r to transition to sysadm_r (if SELinux is > in enforcing mode). Ah, my mistake - the Fedora Core devel policy allows this transition unless you disable the unlimitedUsers tunable. -- Stephen Smalley <sds@xxxxxxxxxxxxxx> National Security Agency