All of lore.kernel.org
 help / color / mirror / Atom feed
From: Stephen Smalley <stephen.smalley.work@gmail.com>
To: Paul Tagliamonte <paultag@debian.org>
Cc: Mike Palmiotto <mike.palmiotto@crunchydata.com>,
	SElinux list <selinux@vger.kernel.org>
Subject: Re: Configuring MLS with a daemon operating at multiple sensitivities
Date: Thu, 14 May 2020 10:50:05 -0400	[thread overview]
Message-ID: <CAEjxPJ4ePzeuhiRdLndM3U7sybjG8QUO8xhd5RuFNH-YB8NB1w@mail.gmail.com> (raw)
In-Reply-To: <CAO6P2QS78aTzCvMHgUWmgmkVjEN9v0Wq0Lgys2puL6eRW+CLjg@mail.gmail.com>

On Thu, May 14, 2020 at 10:01 AM Paul Tagliamonte <paultag@debian.org> wrote:
>
> Hey there Mike,
>
> Incredible! This is very helpful, thank you very much! I think this is
> the missing building block I need.
>
> Have a great day, and thank you to Josh!

Was computing the MLS label the only part you needed?  With respect to
having the daemon run in the same label as the peer (or the label
derived from the intersection of the peer and the daemon), you may
wish to have a look at mod_selinux for Apache and/or the old xinetd
LABELED option, although neither of those would have included the new
glblub support so you'll have to integrate that yourself.  Or your
daemon can just use setcon(3) directly if allowed by policy.

  reply	other threads:[~2020-05-14 14:50 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-05-14 12:45 Configuring MLS with a daemon operating at multiple sensitivities Paul Tagliamonte
2020-05-14 13:55 ` Mike Palmiotto
2020-05-14 14:00   ` Paul Tagliamonte
2020-05-14 14:50     ` Stephen Smalley [this message]
2020-05-14 14:57       ` Paul Tagliamonte
2020-05-14 15:29         ` Stephen Smalley
2020-05-15  0:33           ` Paul Moore

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=CAEjxPJ4ePzeuhiRdLndM3U7sybjG8QUO8xhd5RuFNH-YB8NB1w@mail.gmail.com \
    --to=stephen.smalley.work@gmail.com \
    --cc=mike.palmiotto@crunchydata.com \
    --cc=paultag@debian.org \
    --cc=selinux@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.