Chapter 2. Concepts


In this chapter

  • 2.1 Security Contexts for Type Enforcement

  • 2.2 Type Enforcement Access Control

  • 2.3 The Role of Roles

  • 2.4 Multilevel Security in SELinux

  • 2.5 SELinux Features Familiarization

  • 2.6 Summary

  • Exercises

page 16

page 19

page 29

page 31

page 32

page 36

page 37


The details of the SELinux access control mechanism and policy language are extensive and fully described in later chapters. However, the basic concepts and goals of SELinux are fairly simple. In this chapter, we examine the security concepts of SELinux and the motivations behind these concepts. Gaining a conceptual understanding is necessary to effectively use and apply SELinux access controls. This chapter focuses on the primary access control feature of SELinux, type enforcement (TE), although we also briefly discuss the optional multilevel security mechanism.




SELinux by Example(c) Using Security Enhanced Linux
SELinux by Example: Using Security Enhanced Linux
ISBN: 0131963694
EAN: 2147483647
Year: 2007
Pages: 154

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net