Re: about MAC


From: Amon Ott <ao@rsbac.org>
Subject: Re: about MAC
Date: Wed, 12 Jul 2000 12:36:21 +0200

Next Article (by Subject): ACI...? Jörgen Sigvardsson
Previous Article (by Subject): Re: about MAC Amon Ott
Top of Thread: about MAC Hollace Leon
Articles sorted by: [Date] [Author] [Subject]


On Mit, 12 Jul 2000 Amon Ott wrote:
> On Mit, 12 Jul 2000 Hollace Leon wrote:
> > I was often told: operation not permitted 
> > when I set a security level for a FD as a secoff.
> 
> What is the exact RSBAC syslog message, when this happens?
> 
> > Doesn't secoff  have related rights or else reason?
> 
> You still need Linux rights to see the file/dir. Could this be the problem?

Of course, Security Officer also needs MAC rights to see the files. By default,
secoff (uid 400) is seclevel 0. Raise secoff to maximum, and you can see
everything.

Amon.
-
To unsubscribe from the rsbac list, send a mail to
majordomo@rsbac.org with
unsubscribe rsbac
as single line in the body.

Next Article (by Subject): ACI...? Jörgen Sigvardsson
Previous Article (by Subject): Re: about MAC Amon Ott
Top of Thread: about MAC Hollace Leon
Articles sorted by: [Date] [Author] [Subject]


Go to Compuniverse LWGate Home Page.