
<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/css" href="http://selinuxproject.org/w/skins/common/feed.css?63"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title>NB RBAC - Revision history</title>
		<link>http://selinuxproject.org/w/?title=NB_RBAC&amp;action=history</link>
		<description>Revision history for this page on the wiki</description>
		<language>en</language>
		<generator>MediaWiki 1.10.4</generator>
		<lastBuildDate>Sun, 19 May 2013 01:18:06 GMT</lastBuildDate>
		<item>
			<title>Jaxelson at 20:49, 13 September 2010</title>
			<link>http://selinuxproject.org/w/?title=NB_RBAC&amp;diff=1036&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 20:49, 13 September 2010&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 13:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 13:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;----&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;----&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&amp;lt;references/&amp;gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&amp;lt;references/&amp;gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;[[Category:Notebook]]&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Mon, 13 Sep 2010 20:49:12 GMT</pubDate>			<dc:creator>Jaxelson</dc:creator>			<comments>http://selinuxproject.org/page/Talk:NB_RBAC</comments>		</item>
		<item>
			<title>RichardHaines: New page: = Role-Based Access Control (RBAC) = To further control access to TE domains SELinux makes use of role-based access control (RBAC). This feature allows SELinux users to be associated to on...</title>
			<link>http://selinuxproject.org/w/?title=NB_RBAC&amp;diff=934&amp;oldid=prev</link>
			<description>&lt;p&gt;New page: = Role-Based Access Control (RBAC) = To further control access to TE domains SELinux makes use of role-based access control (RBAC). This feature allows SELinux users to be associated to on...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;= Role-Based Access Control (RBAC) =&lt;br /&gt;
To further control access to TE domains SELinux makes use of role-based access control (RBAC). This feature allows SELinux users to be associated to one or more roles, where each role is then associated to one or more domain types as shown in the [http://taiga.selinuxproject.org/~rhaines/diagrams/4-RBAC.png Role Based Access Control] diagram. Note that GNU / Linux users are not a direct part of the RBAC feature, they are associated to SELinux users via SELinux specific commands&amp;lt;ref name=&amp;quot;ftn6&amp;quot;&amp;gt;&amp;lt;sup&amp;gt;There are other SELinux utilities that can manage users etc., however this Notebook will only use the core utilities.&amp;lt;/sup&amp;gt;&amp;lt;/ref&amp;gt; such as:&lt;br /&gt;
&lt;br /&gt;
* '''semanage login'''- That manages the association of GNU / Linux users (or groups of users) to SELinux users.&lt;br /&gt;
&lt;br /&gt;
* '''semanage user''' - That manages the association of SELinux users to roles. &lt;br /&gt;
&lt;br /&gt;
The [http://taiga.selinuxproject.org/~rhaines/diagrams/4-RBAC.png Role Based Access Control] diagram shows how the SELinux user and roles are associated within the basic loadable modules that form the simple message filter exercise described in Volume 2.&lt;br /&gt;
&lt;br /&gt;
SELinux users can be equated to groups or classes of user, for example in the Reference Policy there is &amp;lt;tt&amp;gt;user_u&amp;lt;/tt&amp;gt; for general users with &amp;lt;tt&amp;gt;staff_u&amp;lt;/tt&amp;gt; and &amp;lt;tt&amp;gt;sysadm_u&amp;lt;/tt&amp;gt; for more specialised users. There is also a &amp;lt;tt&amp;gt;system_u&amp;lt;/tt&amp;gt; defined that must never be associated to a GNU / Linux user as it a special identity for system processes and objects.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;references/&amp;gt;&lt;/div&gt;</description>
			<pubDate>Sun, 16 May 2010 13:56:09 GMT</pubDate>			<dc:creator>RichardHaines</dc:creator>			<comments>http://selinuxproject.org/page/Talk:NB_RBAC</comments>		</item>
	</channel>
</rss>