Casey Schaufler <casey@xxxxxxxxxxxxxxxx> wrote: > This is SELinux specific funtionality and should be done in the > SELinux code. You should not be adding interfaces that are SELinux > specific, in this case using secids instead of the LSM blob interfaces. Is using secids your only objection? Or are you objecting to the whole 'act-as' concept? David