On Thu, 2005-01-27 at 10:36, Daniel J Walsh wrote: > Ah, good point, I wonder if this might be a bug? Is the kernel not > seeing the file as httpdcontent but as nfs_t > even though the mount option was specified. Is the filesystem mounted nosuid? If so, the kernel will ignore domain transitions on it for the same reason as it ignores setuid programs. -- Stephen Smalley <sds@xxxxxxxxxxxxxx> National Security Agency