Excellent! Thanks Sir. -----Original Message----- From: Stephen Smalley [mailto:sds@xxxxxxxxxxxxx] Sent: Wednesday, December 16, 2009 9:48 AM To: Hasan Rezaul-CHR010 Cc: Daniel J Walsh; selinux@xxxxxxxxxxxxx Subject: RE: Policy writing philosophy... On Wed, 2009-12-16 at 10:30 -0500, Hasan Rezaul-CHR010 wrote: > Thanks as always Stephen. > > >> Also can SELinux mappings be created for a Unix Group, as opposed > >> to mapping to individual Linux Users ? > > > Yes - just use %groupname in the seusers configuration. > > Would you kindly give me some more details / examples, or point me to > a URL or document that I can learn more about how to achieve this ? > Thanks again. groupadd research useradd -g research johndoe semanage login -a -s user_u %research ssh -l johndoe localhost id > Also, I have a Fedora 12 machine now. I was wondering, where can I get > all the ***.te files for the corresponding ***.pp files that exist ? yumdownloader --source selinux-policy rpm -ivh selinux-policy*.src.rpm -- Stephen Smalley National Security Agency -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with the words "unsubscribe selinux" without quotes as the message.