Exercises


1.

Create a common permission set named socket with the permissions read, write, bind, connect, and listen.

2.

Associate the common permissions socket and the class-specific permissions connecto and acceptfrom with the object class declared in Question 2.

3.

Write an allow rule that allows the domain httpd_t to append to a file of type httpd_log_t, but not write.

4.

Write the necessary allow rules to allow the domain httpd_t to execute files of type bin_t. Include the ability to request an explicit domain transition but not the ability to execute without transition. Assume that the appropriate rules giving transition and entrypoint are already present in the policy.




SELinux by Example(c) Using Security Enhanced Linux
SELinux by Example: Using Security Enhanced Linux
ISBN: 0131963694
EAN: 2147483647
Year: 2007
Pages: 154

flylib.com © 2008-2017.
If you may any questions please contact us: flylib@qtcs.net