2009-03-05 17:18:34

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] system_locallogin.patch

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

http://people.fedoraproject.org/~dwalsh/SELinux/F11/system_locallogin.patch


Local login uses usb keys for login.

Add unconfined_shell_domtrans which contains a boolean to turn on and
off login as an unconfined user.

local_login now runs well as a confined domain

sulogin calls getpw

sulogin will transition to unconfined_t on non MLS machines.


Redhat does not use pam for sulogin

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkmwCWoACgkQrlYvE4MpobORQACeOjGiOFiIgXfExi5f4Zt7aBFr
xswAnA4MJoZmSgCD33DC87dJvuqDms/O
=v2h9
-----END PGP SIGNATURE-----