[redhat-lspp] Re: MLS enforcing PTYs, sshd, and newrole

Daniel J Walsh dwalsh at redhat.com
Thu Oct 19 13:21:52 UTC 2006


So one proposed solution to this is to take away the newrole -l 
functionality all together and to add Sensitivity selection to the local 
login. 

We can implement pam_selinux to ask for the sensitivity level


username: dwalsh
passwd: ********
Sensitivity: SystemLow

If we then remove -l from newrole we are done?

Dan




More information about the redhat-lspp mailing list