LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-08-2009, 06:41 PM   #1
seramal
LQ Newbie
 
Registered: Aug 2009
Distribution: centos5,fedora11,gentoo
Posts: 3

Rep: Reputation: 0
SELinux - individual security exception


Is it possible to create a new selinux user and assign a certain login to it so that afterwards I can add allow rules specifically for that user?

Say, I have all users in selinux guest_u, but I would like ONLY UNIX user "foobar" to be able to have access to a certain type/domain.

So far, I created the user and assigned the login:
Code:
semanage user -a -R "user_r" -P user testing2_u
semanage login -a -s testing2_u testing2
Any ideas on how to create a rule specially for testing2_u?

#only_user_testing2_u...
allow blabla_t blabla2_t:file execute;
#only_user_testing2_u...
 
Old 08-08-2009, 07:12 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Dan Walsh added that kind of sandboxing to Fedora (whose rules are evolving way faster than RHEL/Centos) in the form of the xguest (or something similar-sounding), if you check out his web log at http://danwalsh.livejournal.com/ you'll probably find it. Let us know if that isn't what you're looking for and BTW please fill in your distro nfo in your http://www.linuxquestions.org/questions/usercp.php .
 
Old 08-08-2009, 08:26 PM   #3
seramal
LQ Newbie
 
Registered: Aug 2009
Distribution: centos5,fedora11,gentoo
Posts: 3

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by unSpawn View Post
Dan Walsh added that kind of sandboxing to Fedora (whose rules are evolving way faster than RHEL/Centos) in the form of the xguest (or something similar-sounding), if you check out his web log at http://danwalsh.livejournal.com/ you'll probably find it. Let us know if that isn't what you're looking for and BTW please fill in your distro nfo in your http://www.linuxquestions.org/questions/usercp.php .
I emailed Dan Walsh because I couldn't find/understand guest.te rules. My problem is very simple, I just need to know how to add per-user allow rules in selinux.

Thanks for replying!
 
Old 08-09-2009, 06:14 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
They should be in Fedora since F10 IIRC, note there's also a selinux users mailing list that probably has search-enabled archives, but let us know what he says, OK?
 
Old 08-09-2009, 01:42 PM   #5
seramal
LQ Newbie
 
Registered: Aug 2009
Distribution: centos5,fedora11,gentoo
Posts: 3

Original Poster
Rep: Reputation: 0
Quote:
Originally Posted by unSpawn View Post
They should be in Fedora since F10 IIRC, note there's also a selinux users mailing list that probably has search-enabled archives, but let us know what he says, OK?
I found a way, theoretically, to achieve what I'm searching for. It seems that I only have to create a role for each user and optionally a domain so in the end I have something like this:

Code:
user1_u:user1_r:user1_t:s0
Then, I could either allow user1_r to do everything user_r does, or actually allowing exactly what user1_u will do in the machine.

The problem is, fedora's 10/11 guest.te/guest.if isn't compatible with centos5 selinux development installation and I don't trust fedora for a production machine (not that unlikely yum upgrade will wreak havoc).

Anyone else, any ideas?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Key Security: Symmetric Encrypting Individual Files mmmmtmmmm Linux - Security 4 12-30-2007 01:25 AM
SELinux Security Level Configuration modernsaint Linux - Security 2 12-10-2007 01:21 AM
security, desktop, selinux, samba issues ciscohead Fedora 1 01-07-2006 05:14 PM
Re: SElinux and OpenBSD security versus other OS? wardialer Linux - Security 2 09-10-2004 11:58 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:34 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration