All of lore.kernel.org
 help / color / mirror / Atom feed
* MLS telnet question
@ 2010-04-09 12:02 Benedict, Phillip M
  2010-04-13 15:21 ` Daniel J Walsh
                   ` (2 more replies)
  0 siblings, 3 replies; 10+ messages in thread
From: Benedict, Phillip M @ 2010-04-09 12:02 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 1068 bytes --]


Hello,

I am trying to come to a solution regarding the use of telnet on our MLS system. ( I know, ... the decision to use it was made above me ) . :(

What we have is a RHEL 5.3 system with the RedHat MLS policy installed.
The system has multiple physical NICs attached to different networks.
Each network is designated for it's own sensitivity level. ( so we might have one network for s1:c20, one for s2:c40 etc...)
User accounts are created with sensitivity labeling via semange. ( so we might have: user1 with s1:c20, and user2 with s2:c40 etc... )
The network does not carry any cipso data for evaluation by my server, so I don't think I can use netlabel.

Questions:
If I use IPTables/SECMARK to apply sensitivity labels to the packets as they come into the system, will xinetd spawn the telnet session with a matching sensitivity?  ( currently the telnet sessions are spawned at SystemLow-SystemHigh )
If telnet is spawned with the appropriate sensitivity, will SELinux disallow a users login who do not have  a matching sensitivity?


Thanks,
Mike Benedict


[-- Attachment #2: Type: text/html, Size: 3552 bytes --]

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2010-04-14 18:33 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2010-04-09 12:02 MLS telnet question Benedict, Phillip M
2010-04-13 15:21 ` Daniel J Walsh
2010-04-13 16:18 ` Stephen Smalley
2010-04-13 16:42 ` Michal Svoboda
2010-04-13 21:54   ` Paul Moore
2010-04-14 12:23     ` Benedict, Phillip M
2010-04-14 13:04       ` Michal Svoboda
2010-04-14 14:30       ` Paul Moore
2010-04-14 17:34         ` Benedict, Phillip M
2010-04-14 18:33           ` Paul Moore

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.