Hi, It seems there is/was a problem using NFS security labels where the server and client use different MAC policy or model. I was reading this page, http://www.selinuxproject.org/page/Labeled_NFS/TODO#Label_Translation_Framework It seems like this problem was known in 2009 when this page was written. Is there a way to accomplish having extended attributes shared over NFS to a client with different selinux policies ? Maybe it's possible to allow the client to write local file context without writing that down to the remote filesystem. Thanks, Daniel