Hi, >From what I understand, given the SELinux framework... EVERY THING by default is Denied, *except* what the policy explicitly allows... How can I configure things (if at all possible), such that EVERY THING by default is Allowed, *except* the specific things Denied in the policy !! Is this doable ? -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with the words "unsubscribe selinux" without quotes as the message.