[DSE-User] mapping of linux users to selinux users fails on login

Erich Schubert erich at vitavonni.de
Sat Nov 10 01:29:30 UTC 2007


Hello Philip,
Sorry for replying so late. I havn't been working on SELinux for the
last few months, and I've actually forgotten much of what I used to
know.

My policy branch contained an extension I called "netuser". It was a
modified user_r role that had extended network capabilities, such as
being able to run a server on an unprivileged port. I created that role
for running my IRC bouncer.
For that I had the same problem to solve as you have: the user should
log into netuser_r instead of user_r.
Unfortunately, I don't remember all the steps I needed to get that
working. But it is working on etch with just my modified policy.
I remember that it took me some time to get everything working like I
wanted (root login as sysadm_r directly, netuser_r login for the user
running the bouncer), but somehow I managed... sorry again for not
having more detailed information for you any more.

best regards,
Erich Schubert
-- 
   erich@(vitavonni.de|debian.org)    --    GPG Key ID: 4B3A135C    (o_
     The future is here. It's just not evenly distributed yet.      //\
          Liebe ist eine schwere Geisteskrankheit (Platon)          V_/_




More information about the Selinux-user mailing list