I branched refpolicy for the RBAC separation, and began the new constraints. I'm trying to decide what to do with the process permissions rlimitinh, siginh, and noatsecure. Since these go with a transition, it seems that they could be added the the existing role constraint on transition. Opinions? -- Chris PeBenito Tresys Technology, LLC (410) 290-1411 x150 -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with the words "unsubscribe selinux" without quotes as the message.