Re: SELinux policy for Xen with CloudStack

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 04/29/2015 12:52 PM, Andrew Holway wrote:
> Hi,
> 
> I have a customer that is asking me to make investigations about setting
> up CloudStack with SELinux. I asked Daniel Walsh and it seems that KVM
> is covered with sVirt in Libvirt however XenServer is a big question
> mark. Should I assume that no work has been done to cover Xen with SELinux?

In the case of Xen, the correct question is whether it is using the XSM
framework and Flask security module (effectively SELinux for the Xen
hypervisor, if you like), and whether they are using SELinux to harden
dom0 and confine any qemu instances.  I don't know offhand whether they
are doing so in CloudStack / XenServer.


_______________________________________________
Selinux mailing list
Selinux@xxxxxxxxxxxxx
To unsubscribe, send email to Selinux-leave@xxxxxxxxxxxxx.
To get help, send an email containing "help" to Selinux-request@xxxxxxxxxxxxx.




[Index of Archives]     [Selinux Refpolicy]     [Linux SGX]     [Fedora Users]     [Fedora Desktop]     [Yosemite Photos]     [Yosemite Camping]     [Yosemite Campsites]     [KDE Users]     [Gnome Users]

  Powered by Linux