Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: Michael Reilly <michaelr@×××××.com>
Cc: Hardened Gentoo Mail List <gentoo-hardened@g.o>
Subject: Re: [gentoo-hardened] Call for policy and devs (was: qmail on selinux)
Date: Sat, 29 Nov 2003 01:43:52
Message-Id: 1070070231.26294.37.camel@chris.pebenito.net
In Reply to: Re: [gentoo-hardened] Call for policy and devs (was: qmail on selinux) by Michael Reilly
1 On Fri, 2003-11-28 at 15:18, Michael Reilly wrote:
2 > Do you have any guidelines for things like supported roles (I have user_r,
3 > staff_r, sysadm_r and am integrating portage from the gentoo policy)?
4
5 I'm not sure what you're asking. But there Gentoo base policy has three
6 roles (user_r, staff_r, sysadm_r, and portage_r). User_r is only for
7 regular users, admins use staff_r and sysadm_r. Admins that can run
8 portage have portage_r too. Except for portage, which is a limited
9 role, all of the full roles show up in the policy/domains/*.te. I split
10 staff_r out of user.te since user_r and staff_r are logically separate,
11 and it makes it easier to add in extra abilities to staff_r if wanted.
12
13 > I also notice that gentoo sets up the user's slightly differently than NSA -
14 > gentoo has the username in the context for staff_r, for example. Any other
15 > things I should know about?
16
17 When users create files, the files have the identity of the user in the
18 context, and this is desired. Normally users can relabel their files to
19 a few different contexts (like httpd_user_content_t for apache
20 ~/public_html directories). However, the identity on the files has to
21 match the identity of the user, unless its a special role, like
22 sysadm_r. This is specified in the constraints file.
23
24 > I may also be interested in being a policy dev. Any special requirements?
25
26 No extra requirements. In general, the Hardened team looks for people
27 with ability, but also for people that are willing to be invested in the
28 project, and can function in team. We're not asking that you ignore
29 your real life responsibilities, but try to be around a reasonable
30 amount of time, for contributing, taking bugs, etc. We don't want
31 people to disappear all of a sudden. So for those who really interested
32 in becoming devs, the best way is, if possible, to be in the IRC
33 channel, speak up, and contribute. In short, if you want to become a
34 dev, act like one :)
35
36 --
37 Chris PeBenito
38 <pebenito@g.o>
39 Developer,
40 Hardened Gentoo Linux
41 Embedded Gentoo Linux
42
43 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
44 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature