1 |
On Fri, 2003-11-28 at 15:18, Michael Reilly wrote: |
2 |
> Do you have any guidelines for things like supported roles (I have user_r, |
3 |
> staff_r, sysadm_r and am integrating portage from the gentoo policy)? |
4 |
|
5 |
I'm not sure what you're asking. But there Gentoo base policy has three |
6 |
roles (user_r, staff_r, sysadm_r, and portage_r). User_r is only for |
7 |
regular users, admins use staff_r and sysadm_r. Admins that can run |
8 |
portage have portage_r too. Except for portage, which is a limited |
9 |
role, all of the full roles show up in the policy/domains/*.te. I split |
10 |
staff_r out of user.te since user_r and staff_r are logically separate, |
11 |
and it makes it easier to add in extra abilities to staff_r if wanted. |
12 |
|
13 |
> I also notice that gentoo sets up the user's slightly differently than NSA - |
14 |
> gentoo has the username in the context for staff_r, for example. Any other |
15 |
> things I should know about? |
16 |
|
17 |
When users create files, the files have the identity of the user in the |
18 |
context, and this is desired. Normally users can relabel their files to |
19 |
a few different contexts (like httpd_user_content_t for apache |
20 |
~/public_html directories). However, the identity on the files has to |
21 |
match the identity of the user, unless its a special role, like |
22 |
sysadm_r. This is specified in the constraints file. |
23 |
|
24 |
> I may also be interested in being a policy dev. Any special requirements? |
25 |
|
26 |
No extra requirements. In general, the Hardened team looks for people |
27 |
with ability, but also for people that are willing to be invested in the |
28 |
project, and can function in team. We're not asking that you ignore |
29 |
your real life responsibilities, but try to be around a reasonable |
30 |
amount of time, for contributing, taking bugs, etc. We don't want |
31 |
people to disappear all of a sudden. So for those who really interested |
32 |
in becoming devs, the best way is, if possible, to be in the IRC |
33 |
channel, speak up, and contribute. In short, if you want to become a |
34 |
dev, act like one :) |
35 |
|
36 |
-- |
37 |
Chris PeBenito |
38 |
<pebenito@g.o> |
39 |
Developer, |
40 |
Hardened Gentoo Linux |
41 |
Embedded Gentoo Linux |
42 |
|
43 |
Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243 |
44 |
Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243 |