[redhat-lspp] Xinetd patches for selinux context configuration

James Antill jantill at redhat.com
Wed Nov 29 22:10:14 UTC 2006


On Wed, 2006-11-29 at 16:32 -0500, Stephen Smalley wrote:

> I'm not sure the approach is quite workable yet either - if you
> configure xinetd to use labeled networking but the incoming connection
> is coming from a host that doesn't support it, getpeercon() will fail
> and you need to gracefully deal with it (e.g. fall back to some default,
> possibly based on the client machine's address).

 Isn't this exactly what netlabel is for? Do we really want to duplicate
that for each daemon?

-- 
James Antill <jantill at redhat.com>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part
URL: <http://listman.redhat.com/archives/redhat-lspp/attachments/20061129/cebccab5/attachment.sig>


More information about the redhat-lspp mailing list