Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] selinux novice
Date: Sun, 22 Jul 2012 18:02:13
Message-Id: 20120722160752.GA10344@gentoo.org
In Reply to: Re: [gentoo-hardened] selinux novice by Ivan Gooten
1 On Sun, Jul 22, 2012 at 01:55:08PM +0200, Ivan Gooten wrote:
2 [...]
3 > which results in console for user root context like
4 > "root:sysadm_r:sysadm_t",
5
6 That's good.
7
8 > whereas in X11 terminal, (after switching from ivan user to root by su -)
9 > -> "staff_u:staff_r:staff_t".
10
11 That's almost good ;-)
12
13 > I understand that in X11 term I'll have to "newrole -r sysadm_r" for root
14 > everytime, when I will want to administrate the system?
15
16 Yes, you need to switch roles (first switch roles, then use su(do)) every
17 time you need to do administrative changes (or queries) on the system. The
18 staff_r role is for regular operations (user) whereas sysadm_r is for system
19 administration.
20
21 > And what about the context's difference between root (root:...) logged from
22 > console and root (staff_u:...) logged via x11 terminal - is that wrong?
23
24 No, that's not wrong. If you log on directly as root, then your SELinux user
25 (the first part in the context) is "root". If you log on as someone else,
26 you get that SELinux user (such as "staff_u") which remains throughout your
27 session (SELinux users don't change, even when you do "su").
28
29 Wkr,
30 Sven Vermeulen

Replies

Subject Author
Re: [gentoo-hardened] selinux novice Ivan Gooten <ivanogot@×××××.com>