On 06/06/2014 08:34 AM, dE wrote: > I'm learning SELinux on Fedora, here if you need to use MLS, you need to > remove TE model cause the MLS is implemented in a completely different > policy. > > Is it possible to create a policy which supports both RABC/TE with MLS? I've explained this previously, but to repeat it: RBAC/TE is always enabled in the SELinux security server (and in the policy), only MLS is optional. So in Fedora, the -mls policy is in truth a RBAC/TE/MLS policy. And in Fedora, the -targeted policy is in truth a RBAC/TE/MCS policy. They both enable the MLS engine in the security server; they only differ in the configuration (policy/mls versus policy/mcs). _______________________________________________ Selinux mailing list Selinux@xxxxxxxxxxxxx To unsubscribe, send email to Selinux-leave@xxxxxxxxxxxxx. To get help, send an email containing "help" to Selinux-request@xxxxxxxxxxxxx.