Re: user guide draft: "Confined and Unconfined User Domains" review

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Dominick Grift wrote:
> On Mon, 2008-09-15 at 12:12 +1000, Murray McAllister wrote:
> 
>> What sudo access does staff_t have?
> 
> I think staff can transition to all privileged user domains
> 
> secadm,logadm,webadm,auditadm,unconfined,sysadm etc. You can verify this
> in the staff role module in the source policy. staff_t may also be root
> however this root as staff_t will have the same permission as staff_t as
> unprivileged user.
> 
Well not in targeted policy.
Out of the box
sesearch --role_allow | grep staff
   allow staff_r sysadm_r;
   allow system_r staff_r;
   allow staff_r unconfined_r;
   allow staff_r webadm_r;

This means staff_r can become sysadm_r, unconfined_r and webadm_r in
Fedora 9/10 targeted policy.
>> --
>> This message was distributed to subscribers of the selinux mailing list.
>> If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with
>> the words "unsubscribe selinux" without quotes as the message.


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with
the words "unsubscribe selinux" without quotes as the message.

[Index of Archives]     [Selinux Refpolicy]     [Linux SGX]     [Fedora Users]     [Fedora Desktop]     [Yosemite Photos]     [Yosemite Camping]     [Yosemite Campsites]     [KDE Users]     [Gnome Users]

  Powered by Linux