2013-10-25 15:45:40

by Gary_Cliff

[permalink] [raw]
Subject: [refpolicy] SELinux Reference Policy

Hi



I'm just getting familiar with the reference policies, and I'm looking for
the following:



- An example ref policy with a description of what it is supposed
to secure (i.e. the policy architecture/design)

- A set of test scripts to verify the reference policy is meeting
its goals (i.e. the description above)



Do these exist?

I'm aware of policies that are available to download/install but these
packages don't include descriptions.



( I have the book SELinux by Example)

Thx

Gary Cliff





-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://oss.tresys.com/pipermail/refpolicy/attachments/20131025/94808297/attachment.html


2013-10-25 17:09:27

by dominick.grift

[permalink] [raw]
Subject: [refpolicy] SELinux Reference Policy

On Fri, 2013-10-25 at 11:45 -0400, Gary Cliff wrote:
> Hi
>
>
>
> I'm just getting familiar with the reference policies, and I'm looking for
> the following:
>
>
>
> - An example ref policy with a description of what it is supposed
> to secure (i.e. the policy architecture/design)
>

The "project goals" are stated here:
http://oss.tresys.com/projects/refpolicy


> - A set of test scripts to verify the reference policy is meeting
> its goals (i.e. the description above)
>

The policy analysis tools can be found here:
http://oss.tresys.com/projects/setools


The selinux test-suite can be found here:
http://git.selinuxproject.org/git/?p=users/serge/selinux-testsuite.git;a=summary

>
>
> Do these exist?
>
> I'm aware of policies that are available to download/install but these
> packages don't include descriptions.

They do, it can be generated with "make html"

Here is a online browsable version:

http://oss.tresys.com/docs/refpolicy/api/

>
>
>
> ( I have the book SELinux by Example)
>
> Thx
>
> Gary Cliff
>
>
>
>
>
> _______________________________________________
> refpolicy mailing list
> refpolicy at oss.tresys.com
> http://oss.tresys.com/mailman/listinfo/refpolicy