newrole using SELinux user identity for password lookups

Colin Walters walters at redhat.com
Wed Apr 21 20:15:04 UTC 2004


On Wed, 2004-04-21 at 15:56, Stephen Smalley wrote:

> In the short term, if you want to have it fall back to the Linux uid for
> authentication purposes if the SELinux user identity is
> SELINUX_DEFAULTUSER (defined in include/selinux/get_context_list.h),
> then that is fine.  Just don't use the Linux uid as the user identity
> for the new context.

Ah, I didn't know about SELINUX_DEFAULTUSER.  Cool.  Patch attached
then.  Tested in both the explicit user identity and default cases.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: policycoreutils-1.10-getuid-fallback.patch
Type: text/x-patch
Size: 1598 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/fedora-selinux-list/attachments/20040421/851a4ad2/attachment.bin>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
URL: <http://listman.redhat.com/archives/fedora-selinux-list/attachments/20040421/851a4ad2/attachment.sig>


More information about the fedora-selinux-list mailing list