PDA

View Full Version : SELINUX status


norrtull
18th December 2004, 08:35 AM
Is anyone updated on the SELINUX and ipsec_tools. Last time I played around with this
I understood that it was not possible to specify SecurityPolicies's down to port level. Only IP dest and source were supported. Now, I dont remember if this was a limitation in SELINUX or in setkey. Anybody up to date on this?
Today (FE3) when I write a SP to the database specifying port numbers the
port numbers are set to 0, when I view the contents of the database (SPD).

Also, I cant find any good user-documentation on this, execpt for man-pages. Anybody found something?

james_in_denver
18th December 2004, 05:49 PM
I know the SELinux in Fedora Core 3 has port level security now,

Here are some documentation links for you,

http://www.nsa.gov/selinux/papers/policy2/t1.html

http://www.nsa.gov/selinux/papers/policy2/x110.html