Adding roles to the Gentoo Hardened SELinux policy

I wrote a small section on how to create additional roles to the SELinux policy offered by Gentoo Hardened. Whereas the default policy that we provide only offers a few basic roles, any policy administrator can provide additional roles for the system.

By using additional roles, you can grant users administrative rights to particular services without risking having them elevate their privileges to root (+ sysadmin). You should even allow them to get a root shell while remaining confined within their domain (and role).

This entry was posted in Hardened, SELinux. Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>