[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: sshd transition points
On Tue, 2005-02-15 at 10:53, Luke Kenneth Casson Leighton wrote:
> so basically, my question boils down to this:
>
> * _should_ sshd, after a fork, be still running in sshd_t?
I'm not sure I follow your posting. Transitions normally only occur
upon execve. sshd should transition upon executing the shell, of
course. IIRC, there is an issue with regard to SELinux not being able
to fully leverage the privilege separation support in sshd since that
requires dynamic transitions. Of course, since dynamic transition
support now exists, someone could look into changing sshd to use it for
finer-grained privilege bracketing.
--
Stephen Smalley <sds@xxxxxxxxxxxxxx>
National Security Agency
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with
the words "unsubscribe selinux" without quotes as the message.
This mailing list archive is a service of Copilot Consulting.