Hi Bill, Hello Phil: Thank you for the suggestion. I have tried the steps from the URL that you provided without success. I get an error when I try to assign Linux user mary to an SELinux login as follows: # cat /etc/redhat-release I would appreciate any hints on how to resolve that error. Thanks! Bill
Have you thought about using categories? https://www.centos.org/docs/5/html/Deployment_Guide-en-US/sec-mcs-getstarted.html Cheers Phil Bill D ---24/05/2017 09:52:00---Greetings: I have been trying to figure out how to control the execution of Java From: Bill D <littus@xxxxxxxxxx> To: selinux@xxxxxxxxxxxxxxxxxxxxxxx Cc: littus@xxxxxxxxxx Date: 24/05/2017 09:52 Subject: Controlling execution of Java JAR files with SELinux RBAC Greetings: I have been trying to figure out how to control the execution of Java JAR files with SELinux RBAC. I have two Linux users named joe and mary and two Java JAR files named jack.jar and mary.jar. Here is how jack executes jack.jar: java -jar jack.jar Here is how mary executes mary.jar: java -jar mary.jar I would like SELinux RBAC to prevent jack from executing mary.jar and prevent mary from executing jack.jar. How to configure SELinux RBAC to make that happen? I have tried various approaches without success. I have also tried the steps in http://forums.fedoraforum.org/archive/index.php/t-222938.html without success. I would greatly appreciate any hints. Regards, Bill _______________________________________________ selinux mailing list -- selinux@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to selinux-leave@xxxxxxxxxxxxxxxxxxxxxxx _______________________________________________ selinux mailing list -- selinux@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to selinux-leave@xxxxxxxxxxxxxxxxxxxxxxx |
_______________________________________________ selinux mailing list -- selinux@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to selinux-leave@xxxxxxxxxxxxxxxxxxxxxxx