SELinux and RHEL are different then other "Trusted" operating systems, in that all software components are the same whether you are running MLS, Strict or Targeted policy. We are not shipping a RHEL5 and a Trusted RHEL5. There is one Kernel, one set of user land packages. The only difference is the Policy installed on the system, and the labels/contexts associated with the files. The steps to switch from a targeted system to an MLS machine is:
- Install selinux-policy-mls
- vi /etc/selinux/config and change SELINUXTYPE to mls
- touch ./autorelabel; reboot
- When the machine is rebooting, put it in permissive mode by adding enforcing=0 to the boot line
- When the machine comes up login and setenforce 1
- The machine is now in MLS mode and will enforce all forms of MAC.
One key componant required to get LSPP is polyinstatiated file systems. Polyinstatiation means that different login sessions looking at the same directory (/tmp) see different contents, depending on things like the username, role, sensitivity level. This allows us to save Top Secret Documents and Secret Documents both in the virtual /tmp and apps running at Secret looking in /tmp see Secret files, Top Secret processes see Top Secret Documents.
So what is in it for those of you who don't use MLS, well polyinstatiation can actually help in a shared targeted machine. If you allow multiple users to log on to a system. You can give each one thier own /tmp and /var/tmp (Or share any other directory). This prevents them from doing shared directory attacks. Polyinstatiation is implemented via a change to the kernel that allows the creation of namespaces. pam_namespace.so allows you to configure login sessions, to run in different namespace. You can read the read man pam_namespace, man namespace.conf to find out how to set this up. Russell Coker has an excellent paper describing pam_namespace also.
Polyinstatiation takes a while to get used to. You can easily get confused. When I experimented around with pam_namespace, I found a couple of problems, and a bug. The first time I set it up I did not mark the directories as described in Russell's Paper.
mount --make-shared /
mount --bind /tmp /tmp
mount --make-private /tmp
mount --bind /var/tmp /var/tmp
mount --make-private /var/tmp
These lines should be added in a rc.local script or some init script. Because if you setup the polyinstatioation and log in as a normal user, then execute one of these commands or the mount command, it will only effect your current namespace, when you log out, these mounts will be removed and will not effect other logged in sessions. So you need this set on the initial namespace, IE Set at boot time. So if you execute these commands and login later to mount a directory outside of /tmp or /var/tmp, all namespaces will see it.
I found a bug in pam_namespace also. I setup namespaces to work for non root accounts. Also I setup the pam_namespace to unmnt_only when I su to root. But the code path in pam_namespace checked if the uid was polyinstatiated first and exited out before call the unmnt_only code path. So this caused the /tmp, and /var/tmp directories to be still mounted when I was root. Not what I wanted. pam_namespace.so has been fixed in Rawhide, and there is a fix in pam-0.99.6.2-3.15.fc6 for FC6, is in testing as of this writing. This fix should get into RHEL5 by Update 1.
In conclusion, this tool has some use outside of MLS environments and might be something an Admin wants to play around with.
Im New
(Anonymous)
2008-03-14 01:55 am (UTC)
Im New...
aMBIXsCfUAS
(Anonymous)
2008-03-16 10:16 pm (UTC)
2008-04-18 09:02 am (UTC)
2008-04-18 09:02 am (UTC)
Latest Hi Tech News
2008-05-03 05:32 pm (UTC)
Opensource news
2008-05-03 05:33 pm (UTC)
Latest Hi Tech News
2008-05-04 09:10 pm (UTC)
Here You Will Find The Web's Best Ever Sex Blog With Loads Of Free Porn Videos Updated Daily.
http://groups.google.us/group/animalpor
They actually look at different directories using the same path.
danwalsh.
http://groups.google.us/group/animal-se
2007-12-03 12:14 am UTC (link) Track This
So user a looking at /tmp see's a different directory then user b looking at /tmp.
Re: Latest Hi Tech News
2008-05-06 03:37 pm (UTC)
http://groups.google.us/group/freeviewm
http://groups.google.us/group/xnxx-a
http://groups.google.us/group/keezmovie
http://groups.google.us/group/shagg
http://groups.google.us/group/penizbot-
http://groups.google.us/group/grayv
http://groups.google.us/group/veqq
http://groups.google.us/group/humor
http://groups.google.us/group/yazu
http://groups.google.us/group/blup
http://groups.google.us/group/pornthund
http://groups.google.us/group/xhamster
http://groups.google.us/group/ohsl
http://groups.google.us/group/deviantcl
http://groups.google.us/group/pornminde
http://groups.google.us/group/madthumbs
http://groups.google.us/group/megapornd
http://groups.google.us/group/duck
http://groups.google.us/group/filt
http://groups.google.us/group/tiav
http://groups.google.us/group/elephantl
http://groups.google.us/group/vidc
http://groups.google.us/group/gals
http://groups.google.us/group/teen
http://groups.google.us/group/qpor
http://groups.google.us/group/sublimedi
http://groups.google.us/group/sock
http://groups.google.us/group/bulldogli
http://groups.google.us/group/sexz
http://groups.google.us/group/efuk
http://groups.google.us/group/pandamovi
http://groups.google.us/group/mrpe
http://groups.google.us/group/myhomecli
http://groups.google.us/group/onetwopor
http://groups.google.us/group/hothomema
http://groups.google.us/group/fuzz
http://groups.google.us/group/slutload
http://groups.google.us/group/bighomemo
http://groups.google.us/group/tehp
http://groups.google.us/group/needbang
http://groups.google.us/group/bravoteen
http://groups.google.us/group/milf
http://groups.google.us/group/lustypupp
http://groups.google.us/group/persianki
http://groups.google.us/group/gaymovied
http://groups.google.us/group/teenstits
http://groups.google.us/group/gexo
http://groups.google.us/group/needtwax
http://groups.google.us/group/shuf
asdasdasd
2008-05-20 07:00 pm (UTC)
These lines should be added in a rc.local script or some init script. Because if you setup the polyinstatioation and log in as a normal user, then execute one of these commands or the mount command, it will only effect your current namespace, when you log out, these mounts will be removed and will not effect other logged in sessions. So you need this set on the initial namespace, IE Set at boot time. So if you execute these commands and login later to mount a directory outside of /tmp or /var/tmp, all namespaces will see it.
http://groups.google.fr/group/free-anim
In conclusion, this tool has some use outside of MLS environments and might be something an Admin wants to play around with.
http://groups.google.fr/group/shockingt
In conclusion, this tool has some use outside of MLS environments and might be something an Admin wants to play around with.
http://groups.google.fr/group/free-anim
In conclusion, this tool has some use outside of MLS environments and might be something an Admin wants to play around with.
http://groups.google.fr/group/free-anim
In conclusion, this tool has some use outside of MLS environments and might be something an Admin wants to play around with.
http://groups.google.fr/group/anima
In conclusion, this tool has some use outside of MLS environments and might be something an Admin wants to play around with.
http://groups.google.fr/group/zoo-t
In conclusion, this tool has some use outside of MLS environments and might be something an Admin wants to play around with.
http://groups.google.fr/group/free-sext
Re: asdasdasd
2008-05-22 07:06 pm (UTC)
http://groups.google.us/group/animal-se
In conclusion, this tool has some use outside
http://groups.google.us/group/free-anim
In conclusion, this tool has some use outside
http://groups.google.us/group/shockingt
might be something
In conclusion, this tool has some use outside
http://groups.google.us/group/free-anim
In conclusion, this tool has some use outside
http://groups.google.us/group/free-anim
http://groups.google.us/group/anima
might be something
http://groups.google.us/group/zoo-t
http://groups.google.us/group/free-sext
ag
2008-06-09 08:33 pm (UTC)
http://www.google.de/notebook/publi
http://www.google.de/notebook/public/13
http://www.google.de/notebook/public/17
http://www.google.de/notebook/public/05
http://www.google.de/notebook/public/12
http://www.google.de/notebook/public/02
http://www.google.de/notebook/public/09
http://www.google.de/notebook/public/14
http://www.google.de/notebook/public/10
http://www.google.de/notebook/public/02
http://www.google.de/notebook/public/07
http://www.google.de/notebook/public/16
http://www.google.de/notebook/public/13
http://www.google.de/notebook/public/17
http://www.google.de/notebook/public/05
http://www.google.de/notebook/public/12
http://www.google.de/notebook/public/07
http://www.google.de/notebook/public/07
http://www.google.de/notebook/public/07
http://www.google.de/notebook/public/16
http://www.google.de/notebook/public/16
http://www.google.de/notebook/public/16
http://www.google.de/notebook/public/13
http://www.google.de/notebook/public/13
http://www.google.de/notebook/public/13
http://www.google.de/notebook/public/17
http://www.google.de/notebook/public/17
http://www.google.de/notebook/public/17
http://www.google.de/notebook/public/05
http://www.google.de/notebook/public/05
http://www.google.de/notebook/public/05
http://www.google.de/notebook/public/12
http://www.google.de/notebook/public/12
http://www.google.de/notebook/public/12
http://www.google.de/notebook/public/02
http://www.google.de/notebook/public/02
http://www.google.de/notebook/public/02
http://www.google.de/notebook/public/09
http://www.google.de/notebook/public/09
http://www.google.de/notebook/public/09
http://www.google.de/notebook/public/14
http://www.google.de/notebook/public/14
ag
2008-06-09 08:34 pm (UTC)
http://www.google.de/notebook/public/10
http://www.google.de/notebook/public/10
http://www.google.de/notebook/public/10
http://www.google.de/notebook/public/02
http://www.google.de/notebook/public/02
http://www.google.de/notebook/public/02
http://www.google.de/notebook/public/06
http://www.google.de/notebook/public/06
http://www.google.de/notebook/public/06
http://www.google.de/notebook/public/00
http://www.google.de/notebook/public/00
http://www.google.de/notebook/public/00
http://www.google.de/notebook/public/16
http://www.google.de/notebook/public/16
http://www.google.de/notebook/public/16
http://www.google.de/notebook/public/12
http://www.google.de/notebook/public/12
http://www.google.de/notebook/public/07
http://www.google.de/notebook/public/07
http://www.google.de/notebook/public/16
http://www.google.de/notebook/public/16
http://www.google.de/notebook/public/13
http://www.google.de/notebook/public/13
http://www.google.de/notebook/public/17
http://www.google.de/notebook/public/17
http://www.google.de/notebook/public/05
http://www.google.de/notebook/public/05
http://www.google.de/notebook/public/12
http://www.google.de/notebook/public/12
http://www.google.de/notebook/public/02
http://www.google.de/notebook/public/02
http://www.google.de/notebook/public/09
http://www.google.de/notebook/public/09
http://www.google.de/notebook/public/14
http://www.google.de/notebook/public/14
http://www.google.de/notebook/public/10
http://www.google.de/notebook/public/10
http://www.google.de/notebook/public/02
http://www.google.de/notebook/public/02
http://www.google.de/notebook/public/06
http://www.google.de/notebook/public/06
http://www.google.de/notebook/public/00
http://www.google.de/notebook/public/00
http://www.google.de/notebook/public/16
http://www.google.de/notebook/public/16
http://www.google.de/notebook/public/12
http://www.google.de/notebook/public/12
http://www.google.de/notebook/public/14
http://www.google.de/notebook/public/14
qweqwe
2008-06-30 12:04 am (UTC)
http://groups-beta.google.com/group/zoo
http://groups-beta.google.com/group/ext
http://groups-beta.google.com/group/z
http://groups-beta.google.com/group/z
http://groups-beta.google.com/group/k
http://groups-beta.google.com/group/for
http://groups-beta.google.com/group/und
http://groups-beta.google.com/group/ped
http://groups-beta.google.com/group/pre
http://groups-beta.google.com/grou
http://groups-beta.google.com/group/spa
http://groups-beta.google.com/group/lit
http://groups-beta.google.com/group/ene
http://groups-beta.google.com/group/fre
http://groups-beta.google.com/group/fre
http://groups-beta.google.com/group/pis
http://groups-beta.google.com/group/cum
http://groups-beta.google.com/group/ama
http://groups-beta.google.com/group/int
http://groups-beta.google.com/group/ani
http://groups-beta.google.com/group/fre
http://groups-beta.google.com/grou
http://groups-beta.google.com/group/ani
http://groups-beta.google.com/group/bea
2008-07-02 09:56 pm (UTC)