Gentoo Archives: gentoo-hardened

From: "Jan Dušek" <j.d@×××××××××.cz>
To: gentoo-hardened@l.g.o, pebenito@g.o
Subject: Re: [gentoo-hardened] Can't change role to portage_r
Date: Mon, 01 Mar 2004 07:38:27
Message-Id: 4042E868.5060801@most.ujep.cz
In Reply to: Re: [gentoo-hardened] Can't change role to portage_r by "Jan Dušek"
1 Oh, sorry for dup - didn't see Michael's question.
2
3 Jan Du¹ek wrote:
4 > Chris PeBenito wrote:
5 >
6 >> On Fri, 2004-02-27 at 06:13, Jan Du¹ek wrote:
7 >>
8 >>> root # newrole -r portage_r
9 >>> Authenticating root.
10 >>> Password:
11 >>> newrole: incorrect password for root
12 >>
13 >>
14 >>
15 >> I've been looking at this for a while, but haven't figured it out yet.
16 >> I'm not sure when it broke. The sysadm_t auto transition will still
17 >> work.
18 >
19 >
20 > What is auto transition?
21 > Does it mean that if my context is root:sysadm_t:sysadm:r than I'm
22 > supposed to be able to use portage? Because I think I've tried that and
23 > it didn't work (not 100% sure and I can't access that machine right now
24 > to test it).
25 >
26 >> The portage role is mainly for cases where you'd want to limit
27 >> access to portage to less than sysadm_t.
28 >>
29 >>
30 >>> Also I'd like to ask how do I add the root:portage_t:portage_r
31 >>> context to the contexts available straight during login?
32 >>
33 >>
34 >>
35 >> This won't work, because portage_t is not a full userdomain, which is
36 >> what's required to have it show up in login. Even if it showed up, you
37 >> cannot transition from [local|remote]_login_t to portage_t.
38 >>
39 >
40 > --jd
41 >
42 > --
43 > gentoo-hardened@g.o mailing list
44 >
45
46 --
47 gentoo-hardened@g.o mailing list