[redhat-lspp] Re: MLS enforcing PTYs, sshd, and newrole

Daniel J Walsh dwalsh at redhat.com
Thu Oct 19 13:21:52 UTC 2006

So one proposed solution to this is to take away the newrole -l 
functionality all together and to add Sensitivity selection to the local 

We can implement pam_selinux to ask for the sensitivity level

username: dwalsh
passwd: ********
Sensitivity: SystemLow

If we then remove -l from newrole we are done?


More information about the redhat-lspp mailing list