Roles in selinux

Jean-David Beyer jeandavid8 at verizon.net
Mon Sep 29 10:20:01 UTC 2014


On 09/29/2014 02:32 AM, William wrote:
> On my Fedora 20 system, I list roles and I can see:

> semanage user -l

>                 Labeling   MLS/       MLS/                          
> SELinux User    Prefix     MCS Level  MCS Range
> SELinux Roles
> 
> guest_u         user       s0         s0
> guest_r
> root            user       s0         s0-s0:c0.c1023
> staff_r sysadm_r system_r unconfined_r
> staff_u         user       s0         s0-s0:c0.c1023
> staff_r sysadm_r system_r unconfined_r
> sysadm_u        user       s0         s0-s0:c0.c1023
> sysadm_r
> system_u        user       s0         s0-s0:c0.c1023
> system_r unconfined_r
> unconfined_u    user       s0         s0-s0:c0.c1023
> system_r unconfined_r
> user_u          user       s0         s0
> user_r
> xguest_u        user       s0         s0
> xguest_r




On my Red Hat Enterprise Linux Server release 6.5 (Santiago) system, I get:
# semanage user -l

                Labeling   MLS/       MLS/
SELinux User    Prefix     MCS Level  MCS Range
SELinux Roles

git_shell_u     user       s0         s0
git_shell_r
guest_u         user       s0         s0                             guest_r
root            user       s0         s0-s0:c0.c1023
staff_r sysadm_r system_r unconfined_r
staff_u         user       s0         s0-s0:c0.c1023
staff_r sysadm_r system_r unconfined_r
sysadm_u        user       s0         s0-s0:c0.c1023
sysadm_r
system_u        user       s0         s0-s0:c0.c1023
system_r unconfined_r
unconfined_u    user       s0         s0-s0:c0.c1023
system_r unconfined_r
user_u          user       s0         s0                             user_r
xguest_u        user       s0         s0
xguest_r


-- 
  .~.  Jean-David Beyer          Registered Linux User 85642.
  /V\  PGP-Key:166D840A 0C610C8B Registered Machine  1935521.
 /( )\ Shrewsbury, New Jersey    http://linuxcounter.net
 ^^-^^ 06:15:01 up 8 days, 16:07, 3 users, load average: 5.54, 5.35, 5.26


More information about the selinux mailing list