
<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/css" href="http://selinuxproject.org/w/skins/common/feed.css?63"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title>MultiCategorySecurity - Revision history</title>
		<link>http://selinuxproject.org/w/?title=MultiCategorySecurity&amp;action=history</link>
		<description>Revision history for this page on the wiki</description>
		<language>en</language>
		<generator>MediaWiki 1.10.4</generator>
		<lastBuildDate>Sat, 25 May 2013 15:01:42 GMT</lastBuildDate>
		<item>
			<title>ChrisPeBenito at 14:27, 18 November 2009</title>
			<link>http://selinuxproject.org/w/?title=MultiCategorySecurity&amp;diff=798&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 14:27, 18 November 2009&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 1:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 1:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;Mult-Category Security (MCS) is an optional addition in SELinux that allows users to add categories to files.  The number of categories supported by the system is configured by policy; Fedora supports 1024, c0, c1,... c1022, c1023.  Categories can optionally be translated (mapped) into more descriptive names, such as Engineering, Marketing, Payroll, and CompanyNDA.  A file may have multiple categories.  For example, if there was a technical report but it was under a non-disclosure agreement (NDA), the file might have the categores Engineering,CompanyNDA.  The category names can be configured in the ''/etc/selinux/NAME/setrans.conf'' file.&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;Mult-Category Security (MCS) is an optional addition in SELinux that allows users to add categories to &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;processes and &lt;/ins&gt;files.  &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;This adds the additional constraint to the access check requiring that the categories that the process has must be a [[http://en.wikipedia.org/wiki/Superset|superset]] of the categories of the files it is accessing. &lt;/ins&gt;The number of categories supported by the system is configured by policy; Fedora supports 1024, c0, c1,... c1022, c1023.  &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;For example, if a process has categories c1,c3, it can access files that have category c1, files that have category category c3, files that have categories c1 and c3, and files that have no categories.  It will not be able to access a file that has category c4, or a file that has categories c3 and c6.&lt;/ins&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;Categories can optionally be translated (mapped) into more descriptive names, such as Engineering, Marketing, Payroll, and CompanyNDA.  A file may have multiple categories.  For example, if there was a technical report but it was under a non-disclosure agreement (NDA), the file might have the categores Engineering,CompanyNDA.  The category names can be configured in the ''/etc/selinux/NAME/setrans.conf'' file.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; s0:c0=Engineering&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; s0:c0=Engineering&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 23:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 25:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;Now that the file has the correct categories, programs should be run with categories.&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;Now that the file has the correct categories, programs should be run with categories.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt; runcon -l&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt; runcon -l &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Engineering evolution&lt;/ins&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;&amp;#160;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;This will run the evolution email program with the Engineering category.  Now this instance of evolution will be able to attach files with either no categories or the Engineering category.  It will be prevented from accidentally attaching CompanyNDA files, since evolution has the Engineering category, which is not a superset of the CompanyNDA category.&lt;/ins&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Wed, 18 Nov 2009 14:27:41 GMT</pubDate>			<dc:creator>ChrisPeBenito</dc:creator>			<comments>http://selinuxproject.org/page/Talk:MultiCategorySecurity</comments>		</item>
		<item>
			<title>ChrisPeBenito: New page: Mult-Category Security (MCS) is an optional addition in SELinux that allows users to add categories to files.  The number of categories supported by the system is configured by policy; Fed...</title>
			<link>http://selinuxproject.org/w/?title=MultiCategorySecurity&amp;diff=797&amp;oldid=prev</link>
			<description>&lt;p&gt;New page: Mult-Category Security (MCS) is an optional addition in SELinux that allows users to add categories to files.  The number of categories supported by the system is configured by policy; Fed...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;Mult-Category Security (MCS) is an optional addition in SELinux that allows users to add categories to files.  The number of categories supported by the system is configured by policy; Fedora supports 1024, c0, c1,... c1022, c1023.  Categories can optionally be translated (mapped) into more descriptive names, such as Engineering, Marketing, Payroll, and CompanyNDA.  A file may have multiple categories.  For example, if there was a technical report but it was under a non-disclosure agreement (NDA), the file might have the categores Engineering,CompanyNDA.  The category names can be configured in the ''/etc/selinux/NAME/setrans.conf'' file.&lt;br /&gt;
&lt;br /&gt;
 s0:c0=Engineering&lt;br /&gt;
 s0:c1=Marketing&lt;br /&gt;
 s0:c2=Payroll&lt;br /&gt;
 s0:c3=CompanyNDA&lt;br /&gt;
 s0:c0,c3=Engineering_NDA&lt;br /&gt;
&lt;br /&gt;
The s0 portion is required, as MCS is implemented using SELinux's Multi-Level Security (MLS) support.&lt;br /&gt;
&lt;br /&gt;
The categories on a file can be changed by using the chcat command.  For example, to add the CompanyNDA to a file:&lt;br /&gt;
&lt;br /&gt;
 chcat +CompanyNDA myfile.doc&lt;br /&gt;
&lt;br /&gt;
Similarly, to remove the Engineering category:&lt;br /&gt;
&lt;br /&gt;
 chcat -- -Engineering myfile.doc&lt;br /&gt;
&lt;br /&gt;
The ''--'' is required to specify that the categories being removed are not options for chcat.  To completely set the category set (replacing the existing categories):&lt;br /&gt;
&lt;br /&gt;
 chcat Marketing,CompanyNDA myfile.doc&lt;br /&gt;
&lt;br /&gt;
Now that the file has the correct categories, programs should be run with categories.&lt;br /&gt;
&lt;br /&gt;
 runcon -l&lt;/div&gt;</description>
			<pubDate>Wed, 18 Nov 2009 14:18:06 GMT</pubDate>			<dc:creator>ChrisPeBenito</dc:creator>			<comments>http://selinuxproject.org/page/Talk:MultiCategorySecurity</comments>		</item>
	</channel>
</rss>