roles in targeted mode

Daniel J Walsh dwalsh at redhat.com
Tue May 12 18:07:35 UTC 2009


On 05/12/2009 01:14 PM, Brian Ginn wrote:
> After some time learning SELinux on Fedora 9, I'm on an RHEL 5.3 box in targeted mode.
> The policycoreutils rpm doesn't contain the newrole command.  Is newrole even needed in targeted mode?
>
No targeted policy in RHEL5 is basically everything in system_r role.

This is changing in Fedora 9 and beyond.  Where you can have confined 
user roles along with unconfined user roles.
> seinfo -r -x
> reports 6 roles and 268 total types
> It looks like every role is allowed to run every type except for two types:
>         httpd_squid_script_t and httpd_prewikka_script_t
>
>
>
>
>
> Thanks,
> Brian
>
>
>
>
> --
> fedora-selinux-list mailing list
> fedora-selinux-list at redhat.com
> https://www.redhat.com/mailman/listinfo/fedora-selinux-list




More information about the fedora-selinux-list mailing list