Karl MacMillan 9f945b

Status

Chris PeBenito e376ad
Current Version: 20050907
Karl MacMillan 9f945b

Chris PeBenito 2dda6a
	See download for download
Chris PeBenito 698a4a
	information. Details of this release are part of the changelog.
Chris PeBenito e376ad
	This release focused on addition of policies from the NSA example
Chris PeBenito e376ad
	policy.  Currently both strict and targeted policies can be
Chris PeBenito 698a4a
	built.  MLS policies can be built, but the policy has not been tested
Chris PeBenito 698a4a
	on running systems.
Chris PeBenito 2dda6a

Chris PeBenito d299d7

 

Chris PeBenito d299d7

Status and Tasks

Karl MacMillan 1c5008
Chris PeBenito faf0db
	
Karl MacMillan 1c5008
	Reference Policy Status
Karl MacMillan 1c5008
	
Karl MacMillan 1c5008
	
Karl MacMillan 1c5008
	
Karl MacMillan 1c5008
	Task/ComponentStatusDescription
Chris PeBenito faf0db
	
Chris PeBenito faf0db
	
Chris PeBenito faf0db
		Policy Structure
Chris PeBenito faf0db
		Complete
Chris PeBenito faf0db
		The policy is converted over to new Reference Policy structure
Chris PeBenito faf0db
	
Chris PeBenito faf0db
	
Chris PeBenito faf0db
		TE Policy
Chris PeBenito faf0db
		Conversion Ongoing
Chris PeBenito faf0db
		Conversion of old policy to Reference Policy modules is ongoing
Karl MacMillan 44772e
	
Chris PeBenito faf0db
	
Chris PeBenito faf0db
		Loadable Policy Modules
Chris PeBenito faf0db
		Major improvements
Chris PeBenito faf0db
		Infrastructure is in place to support both source policy and
Chris PeBenito c2ecf0
			loadable policy modules.  Makefile support completed.
Chris PeBenito faf0db
	
Karl MacMillan 44772e
	
Chris PeBenito faf0db
		Documentation Infrastructure
Chris PeBenito e376ad
		Interfaces, templates, Booleans, and tunables complete
Chris PeBenito e376ad
		Tools to create webpages from the module interface and 
Chris PeBenito e376ad
			template documentation is complete. Global Booleans and
Chris PeBenito e376ad
			tunables are supported. Booleans and tunables local to
Chris PeBenito e376ad
			policies are planned.
Chris PeBenito faf0db
	
Chris PeBenito faf0db
	
Chris PeBenito faf0db
		Policy Documentation
Chris PeBenito faf0db
		Ongoing
Chris PeBenito e376ad
		Most modules are documented.
Chris PeBenito faf0db
	
Chris PeBenito faf0db
	
Chris PeBenito faf0db
		Unused Modules
Chris PeBenito faf0db
		Complete
Chris PeBenito faf0db
		Modules can be disabled by using modules.conf.
Chris PeBenito faf0db
	
Chris PeBenito faf0db
	
Chris PeBenito faf0db
		MLS Infrastructure
Chris PeBenito faf0db
		Minor improvements
Chris PeBenito faf0db
		MLS infrastructure added to support easy conversion between
Chris PeBenito faf0db
			MLS and non-MLS policy.  Policy is compilable, but
Chris PeBenito e376ad
			untested. Need further investigations to ensure
Chris PeBenito e376ad
			the levels in the policy are correct.
Chris PeBenito faf0db
	
Chris PeBenito faf0db
	
Chris PeBenito faf0db
		Network Infrastructure
Chris PeBenito faf0db
		Minor improvements
Chris PeBenito faf0db
		All network ports, nodes, and interfaces moved to
Chris PeBenito faf0db
			corenetwork module, interfaces generated automatically.
Chris PeBenito faf0db
			Plan to add more infrastructure for configuration of
Chris PeBenito faf0db
			ports, nodes, and interfaces.
Chris PeBenito faf0db
	
Chris PeBenito faf0db
	
Chris PeBenito faf0db
		User domains and roles
Chris PeBenito faf0db
		Minor improvements
Chris PeBenito faf0db
		Some infrastructure added to support per-user domain policy,
Chris PeBenito faf0db
			e.g., to create types and policy for ssh,
Chris PeBenito faf0db
			for each user.  Plan to add infrastructure to easily
Chris PeBenito faf0db
			configure userdomains and roles.
Chris PeBenito faf0db
	
Chris PeBenito faf0db
	
Chris PeBenito faf0db
		Labeling
Chris PeBenito faf0db
		Minor improvements
Chris PeBenito faf0db
		All labeling moved to modules, consistent with Reference
Chris PeBenito e376ad
			Policy structure. Levels can be added to the labels
Chris PeBenito e376ad
			without changes to the policy.
Chris PeBenito faf0db
	
Chris PeBenito faf0db
	
Chris PeBenito faf0db
		Tunables
Chris PeBenito faf0db
		Minor improvements
Chris PeBenito e376ad
		Tunables are documented and included in the webpage policy
Chris PeBenito e376ad
			documentation.
Chris PeBenito faf0db
	
Chris PeBenito faf0db
	
Chris PeBenito faf0db
		Users
Chris PeBenito faf0db
		Unchanged
Chris PeBenito e376ad
		Assignment of users to roles.
Chris PeBenito faf0db
	
Chris PeBenito faf0db
	
Chris PeBenito faf0db
		Constraints
Chris PeBenito faf0db
		Unchanged
Chris PeBenito e376ad
		Plan to split up into relevant modules when loadable modules
Chris PeBenito e376ad
			support this.  There are ordering problems with source
Chris PeBenito e376ad
			policies.
Chris PeBenito faf0db
	
Chris PeBenito faf0db
	
Chris PeBenito faf0db
		Flask
Chris PeBenito faf0db
		Unchanged
Chris PeBenito faf0db
		Headers for the policy, describing object classes, and
Chris PeBenito e376ad
			their permissions.  No planned changes.
Chris PeBenito faf0db
	
Chris PeBenito faf0db
	
Chris PeBenito faf0db
		Genhomedircon
Chris PeBenito faf0db
		Unchanged
Chris PeBenito faf0db
		Tool to properly label users' home directories.
Chris PeBenito faf0db
			No planned changes
Chris PeBenito faf0db
	
Chris PeBenito faf0db
Chris PeBenito d299d7

 

Chris PeBenito d299d7

Roadmap

Chris PeBenito d299d7
Chris PeBenito d299d7
  
Chris PeBenito d299d7
    
Chris PeBenito d299d7
      Reference Policy Roadmap
Chris PeBenito d299d7
    
Chris PeBenito d299d7
    
Chris PeBenito d299d7
      Version
Chris PeBenito d299d7
      Date
Chris PeBenito d299d7
      Description
Chris PeBenito d299d7
    
Chris PeBenito d299d7
    
Chris PeBenito d299d7
      0.1
Chris PeBenito d299d7
      June 2005
Chris PeBenito d299d7
      Initial public release, basic policy restructuring, some infrastructure, few modules, and minimal documentation.
Chris PeBenito d299d7
    
Chris PeBenito d299d7
    
Chris PeBenito d299d7
      0.2
Chris PeBenito d299d7
      July 2005
Chris PeBenito d299d7
      Restructuring complete, additional modules, and improved infrastructure.
Chris PeBenito d299d7
    
Chris PeBenito d299d7
    
Chris PeBenito d299d7
      0.3
Chris PeBenito d299d7
      August 2005
Chris PeBenito d299d7
      Additional modules, documentation, and base module configuration support.
Chris PeBenito d299d7
    
Chris PeBenito d299d7
    
Chris PeBenito d299d7
      0.4
Chris PeBenito d299d7
      September 2005
Chris PeBenito d299d7
      Additional modules, documentation, and tested loadable module support.
Chris PeBenito d299d7
    
Chris PeBenito d299d7
    
Chris PeBenito d299d7
      0.5
Chris PeBenito d299d7
      October 2005
Chris PeBenito d299d7
      Additional modules, documentation, targeted policy, and tested MLS support
Chris PeBenito d299d7
    
Chris PeBenito d299d7
    
Chris PeBenito d299d7
      0.6
Chris PeBenito d299d7
      December 2005
Chris PeBenito d299d7
      Additional modules, documentation, and module variations
Chris PeBenito d299d7
    
Chris PeBenito d299d7
  
Chris PeBenito d299d7
Chris PeBenito d299d7

 

Chris PeBenito 1fe082

Policy Conversion

Chris PeBenito 1fe082

Chris PeBenito 1fe082
This phase of reference policy development involves the conversion of policies
Chris PeBenito e24981
from the example strict policy.  We are updating the baseline to NSA CVS.
Chris PeBenito e24981
Modules that are in the targeted policy are the first priority, and modules
Chris PeBenito e24981
in the strict policy, but not targeted are second priority.
Chris PeBenito e24981
For those who wish to contribute, here is a listing of modules which need to be
Chris PeBenito e24981
converted:
Chris PeBenito f5bf2e

Chris PeBenito f5bf2e
Chris PeBenito f5bf2e
  
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
      Policy Module Status
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
      Module Name
Chris PeBenito f5bf2e
      Previous Policy Files
Chris PeBenito f5bf2e
      Assigned To
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      amanda *+
Chris PeBenito f5bf2e
      amanda.te amanda.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      anaconda *+
Chris PeBenito f5bf2e
      anaconda.te anaconda.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      amavis
Chris PeBenito e24981
      amavis.te amavis.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      apache *+
Chris PeBenito f5bf2e
      apache.te apache.fc apache_macros.te
Chris PeBenito f5bf2e
      Tresys
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      arpwatch *+
Chris PeBenito f5bf2e
      arpwatch.te arpwatch.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      asterisk
Chris PeBenito e24981
      asterisk.te asterisk.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      audio-entropy
Chris PeBenito e24981
      audio-entropyd.te audio-entropyd.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      authbind
Chris PeBenito e24981
      authbind.te authbind.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      automount +
Chris PeBenito f5bf2e
      automount.te automount.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      backup
Chris PeBenito e24981
      backup.te backup.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      bluetooth *+
Chris PeBenito f5bf2e
      bluetooth.te bluetooth.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      bonobo +
Chris PeBenito f5bf2e
      bonobo.te bonobo.fc bonobo_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      browser +
Chris PeBenito f5bf2e
      mozilla.te mozilla.fc mozilla_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      calamaris
Chris PeBenito e24981
      calabaris.te calamaris.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      cdrecord +
Chris PeBenito f5bf2e
      cdrecord.te cdrecord.fc cdrecord_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      certwatch +
Chris PeBenito f5bf2e
      certwatch.te certwatch.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      cipe
Chris PeBenito e24981
      ciped.te ciped.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      clamav
Chris PeBenito e24981
      clamav.te clamav.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      courier
Chris PeBenito e24981
      courier.te courier.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      cvs *+
Chris PeBenito f5bf2e
      cvs.te cvs.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      cyrus *+
Chris PeBenito f5bf2e
      cyrus.te cyrus.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      daemontools
Chris PeBenito e24981
      daemontools.te daemontools.fc daemontools_macros.te
Chris PeBenito e24981
      Tresys
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      dante
Chris PeBenito e24981
      dante.te dante.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      dcc
Chris PeBenito e24981
      dcc.te dcc.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      ddclient
Chris PeBenito e24981
      ddclient.te ddclient.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      ddcprobe +
Chris PeBenito f5bf2e
      ddcprobe.te ddcprobe.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      distcc
Chris PeBenito e24981
      distcc.te distcc.fc
Chris PeBenito e24981
      Tresys
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      djbdns
Chris PeBenito e24981
      djbdns.te djbdns.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      dmidecode *+
Chris PeBenito f5bf2e
      dmidecode.te dmidecode.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      dnsmasq
Chris PeBenito e24981
      dnsmasq.te dnsmasq.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      dpkg
Chris PeBenito e24981
      dpkg.te dpkg.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      dovecot *+
Chris PeBenito f5bf2e
      dovecot.te dovecot.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      ethereal +
Chris PeBenito f5bf2e
      ethereal.te ethereal.fc ethereal_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      evolution +
Chris PeBenito e24981
      evolution.te evolution.fc evolution_macros.te
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      fetchmail +
Chris PeBenito f5bf2e
      fetchmail.te fetchmail.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      finger *+
Chris PeBenito f5bf2e
      fingerd.te fingerd.fc fingerd_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      fontconfig +
Chris PeBenito f5bf2e
      fontconfig.te fontconfig.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      ftp *+
Chris PeBenito f5bf2e
      ftpd.te ftpd.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      gatekeeper
Chris PeBenito e24981
      gatekeeper.te gatekeeper.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      gconf +
Chris PeBenito f5bf2e
      gconf.te gconf.fc gconf_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      games +
Chris PeBenito f5bf2e
      games.te games.fc games_domain.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      gift
Chris PeBenito e24981
      gift.te gift.fc gift_macros.te
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      gnome +
Chris PeBenito f5bf2e
      gnome.te gnome.fc gnome_macros.te gnome_vfs.te gnome_vfs.fc gnome_vfs_macros.te gnome-pty-helper.te gnome-pty-helper.fc gph_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      iceauth +
Chris PeBenito f5bf2e
      iceauth.te iceauth.fc iceauth_macros ice_macros.te(?)
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      imazesrv
Chris PeBenito e24981
      imazesrv.te imazesrv.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      irc +
Chris PeBenito f5bf2e
      irc.te irc.fc irc_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      ircd
Chris PeBenito e24981
      ircd.te ircd.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      irqbalance +
Chris PeBenito f5bf2e
      irqbalance.te irqbalance.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      jabber
Chris PeBenito e24981
      jabberd.te jabberd.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      java +
Chris PeBenito f5bf2e
      java.te java.fc java_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      kudzu *+
Chris PeBenito f5bf2e
      kudzu.te kudzu.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      lcd
Chris PeBenito e24981
      lcd.te lcd.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      lockdev +
Chris PeBenito f5bf2e
      lockdev.te lockdev.fc lockdev_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      lrr
Chris PeBenito e24981
      lrrd.te lrrd.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      mailman *+
Chris PeBenito f5bf2e
      mailman.te mailman.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      monop
Chris PeBenito e24981
      monopd.te monopd.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      mplayer +
Chris PeBenito f5bf2e
      mplayer.te mplayer.fc mplayer_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      mrtg +
Chris PeBenito f5bf2e
      mrtg.te mrtg.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      nagios
Chris PeBenito e24981
      nagios.te nagios.fc nrpe.te nrpe.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      nessus
Chris PeBenito e24981
      nessusd.te nessusd.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      networkmanager *+
Chris PeBenito e24981
      NetworkManager.te NetworkManager.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      nsd
Chris PeBenito e24981
      nsd.te nsd.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      nx
Chris PeBenito e24981
      nx_server.te nx_server.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      oav-update
Chris PeBenito e24981
      oav-update.te oav-update.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      openca
Chris PeBenito e24981
      openca-ca.te openca-ca.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      openct +
Chris PeBenito f5bf2e
      openct.te openct.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      orbit +
Chris PeBenito f5bf2e
      orbit.te orbit.fc orbit_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      perdition
Chris PeBenito e24981
      perdition.te perdition.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      portslave
Chris PeBenito e24981
      portslave.te portslave.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      postfix +
Chris PeBenito f5bf2e
      postfix.te postfix.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      ppp *+
Chris PeBenito f5bf2e
      pppd.te pppd.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      prelink +
Chris PeBenito f5bf2e
      prelink.te prelink.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      print *+
Chris PeBenito f5bf2e
      cups.te cups.fc lpd.te lpd.fc lpr_macros.te
Chris PeBenito f5bf2e
      Tresys
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      procmail +
Chris PeBenito f5bf2e
      procmail.te procmail.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      publicfile
Chris PeBenito e24981
      publicfile.te publicfile.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      pxe
Chris PeBenito e24981
      pxe.te pxe.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      pyzor
Chris PeBenito e24981
      pyzor.te pyzor.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      radius *+
Chris PeBenito f5bf2e
      radius.te radius.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      radvd *+
Chris PeBenito f5bf2e
      radvd.te radvd.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      razor
Chris PeBenito e24981
      razor.te razor.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      rdisc
Chris PeBenito e24981
      rdisc.te rdisc.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      resmgr
Chris PeBenito e24981
      resmgrd.te resmgrd.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      rlogin *+
Chris PeBenito f5bf2e
      rlogind.te rlogind.fc login_macros.te
Chris PeBenito f5bf2e
      Tresys
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      rpc *+
Chris PeBenito e24981
      rpcd.te rpcd.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      rssh
Chris PeBenito e24981
      rssh.te rssh.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      sasl *+
Chris PeBenito f5bf2e
      saslauthd.te saslauthd.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      scannerdaemon
Chris PeBenito e24981
      scannerdaemon.te scannerdaemon.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      screen +
Chris PeBenito f5bf2e
      screen.te screen.fc screen_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      slocate +
Chris PeBenito f5bf2e
      slocate.te slocate.fc slocate_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      slrnpull +
Chris PeBenito f5bf2e
      slrnpull.te slrnpull.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      snort
Chris PeBenito e24981
      snort.te snort.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      sound +
Chris PeBenito e24981
      alsa.te alsa.fc sound.te sound.fc sound-server.te sound-server.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      spamassassin +
Chris PeBenito f5bf2e
      spamassassin.te spamc.te spamd.te spamassassin.fc spamc.fc spamd.fc spamassassin_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      speedtouch
Chris PeBenito e24981
      speedmgmt.te speedmgmt.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      stunnel *+
Chris PeBenito f5bf2e
      stunnel.te stunnel.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      sxid
Chris PeBenito e24981
      sxid.te sxid.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      sysstat +
Chris PeBenito f5bf2e
      sysstat.te sysstat.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      telnet *+
Chris PeBenito f5bf2e
      telnetd.te telnetd.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      thunderbird +
Chris PeBenito f5bf2e
      thunderbird.te thunderbird.fc thunderbird_macros.te mail_client_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      timidity +
Chris PeBenito f5bf2e
      timidity.te timidity.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      tinydns
Chris PeBenito e24981
      tinydns.te tinydns.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      transproxy
Chris PeBenito e24981
      transproxy.te transproxy.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      tripwire
Chris PeBenito e24981
      tripwire.te tripwire.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      tvtime +
Chris PeBenito f5bf2e
      tvtime.te tvtime.fc tvtime_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      ucspi-tcp
Chris PeBenito e24981
      ucspi-tcp.te ucspi-tcp.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      uml +
Chris PeBenito e24981
      uml.te uml.fc uml_macros.te uml_net.te uml_net.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      uptimed
Chris PeBenito e24981
      uptimed.te uptimed.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      userhelper +
Chris PeBenito f5bf2e
      userhelper.te userhelper.fc userhelper_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      usernetctl +
Chris PeBenito f5bf2e
      usernetctl.te usernetctl.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      uucp *+
Chris PeBenito f5bf2e
      uucpd.te uucpd.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      uwimap
Chris PeBenito e24981
      uwimapd.te uwimapd.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      vmware +
Chris PeBenito f5bf2e
      vmware.te vmware.fc vmware_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      vpn +
Chris PeBenito e24981
      vpnc.te vpnc.fc openvpn.te openvpn.fc/td>
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      watchdog
Chris PeBenito e24981
      watchdog.te watchdog.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      webalizer *+
Chris PeBenito f5bf2e
      webalizer.te webalizer.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      winbind *+
Chris PeBenito f5bf2e
      winbind.te winbind.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      xdm *+
Chris PeBenito f5bf2e
      xdm.te xdm.fc xdm_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      xfs +
Chris PeBenito f5bf2e
      xfs.te xfs.fc
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
      xprint
Chris PeBenito e24981
      xprint.te xprint.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      xserver +
Chris PeBenito f5bf2e
      xserver.te xserver.fc xserver_macros.te xauth.te xauth.fc xauth_macros.te
Chris PeBenito f5bf2e
      
Chris PeBenito f5bf2e
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      yam
Chris PeBenito e24981
      yam.te yam.fc
Chris PeBenito e24981
      
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      (*) Modules in the Fedora targeted policy
Chris PeBenito e24981
    
Chris PeBenito e24981
    
Chris PeBenito e24981
      (+) Modules in the Fedora strict policy
Chris PeBenito e24981
    
Chris PeBenito f5bf2e
  
Chris PeBenito f5bf2e
Chris PeBenito fe51b3

Testing Status

Chris PeBenito fe51b3

Chris PeBenito b3e0af
The policy as successfully been booted and can run with a Fedora Core 4
Chris PeBenito fd637c
installation, using a targeted Reference Policy.  See the
Chris PeBenito fd637c
switching guide to switch a Fedora system 
Chris PeBenito fd637c
over to targeted Reference policy configuration.
Chris PeBenito fe51b3
A very minimal RedHat Enterprise Linux 4 system with the following RPMs has
Chris PeBenito fe51b3
can be successfully booted in enforcing mode, and users can log in locally,
Chris PeBenito c2ecf0
with a strict Reference Policy:
Chris PeBenito fe51b3

Chris PeBenito fe51b3
    Chris PeBenito fe51b3
  • libgcc-3.4.3-9.EL4
  • Chris PeBenito fe51b3
  • rootfiles-8-1
  • Chris PeBenito fe51b3
  • filesystem-2.3.0-1
  • Chris PeBenito fe51b3
  • termcap-5.4-3
  • Chris PeBenito fe51b3
  • glibc-common-2.3.4-2
  • Chris PeBenito fe51b3
  • bzip2-libs-1.0.2-13
  • Chris PeBenito fe51b3
  • device-mapper-1.00.19-2
  • Chris PeBenito fe51b3
  • elfutils-libelf-0.97-5
  • Chris PeBenito fe51b3
  • expat-1.95.7-4
  • Chris PeBenito fe51b3
  • glib2-2.4.7-1
  • Chris PeBenito fe51b3
  • libattr-2.4.16-3
  • Chris PeBenito fe51b3
  • libcap-1.10-20
  • Chris PeBenito fe51b3
  • libsepol-1.1.1-2
  • Chris PeBenito fe51b3
  • db4-4.2.52-7.1
  • Chris PeBenito fe51b3
  • libtermcap-2.0.8-39
  • Chris PeBenito fe51b3
  • mktemp-1.5-20
  • Chris PeBenito fe51b3
  • iproute-2.6.9-3
  • Chris PeBenito fe51b3
  • less-382-4
  • Chris PeBenito fe51b3
  • pcre-4.5-3
  • Chris PeBenito fe51b3
  • usbutils-0.11-6.1
  • Chris PeBenito fe51b3
  • vim-minimal-6.3.046-0.40E.4
  • Chris PeBenito fe51b3
  • info-4.7-5
  • Chris PeBenito fe51b3
  • diffutils-2.8.1-12
  • Chris PeBenito fe51b3
  • gawk-3.1.3-10.1
  • Chris PeBenito fe51b3
  • coreutils-5.2.1-31
  • Chris PeBenito fe51b3
  • gzip-1.3.3-13
  • Chris PeBenito fe51b3
  • module-init-tools-3.1-0.pre5.3
  • Chris PeBenito fe51b3
  • procps-3.2.3-7EL
  • Chris PeBenito fe51b3
  • sed-4.1.2-4
  • Chris PeBenito fe51b3
  • MAKEDEV-3.15-2
  • Chris PeBenito fe51b3
  • sysklogd-1.4.1-26_EL
  • Chris PeBenito fe51b3
  • cracklib-2.7-29
  • Chris PeBenito fe51b3
  • pam-0.77-65.1
  • Chris PeBenito fe51b3
  • SysVinit-2.85-34
  • Chris PeBenito fe51b3
  • lvm2-2.00.31-1.0.RHEL4
  • Chris PeBenito fe51b3
  • kernel-2.6.9-5.0.5.EL
  • Chris PeBenito fe51b3
  • libuser-0.52.5-1
  • Chris PeBenito fe51b3
  • crontabs-1.10-7
  • Chris PeBenito fe51b3
  • tmpwatch-2.9.1-1
  • Chris PeBenito fe51b3
  • m4-1.4.1-16
  • Chris PeBenito fe51b3
  • mgetty-1.1.31-2
  • Chris PeBenito fe51b3
  • time-1.7-25
  • Chris PeBenito fe51b3
  • dhclient-3.0.1-12_EL
  • Chris PeBenito fe51b3
  • samhain-2.0.6-1
  • Chris PeBenito fe51b3
  • hwdata-0.146.1.EL-1
  • Chris PeBenito fe51b3
  • redhat-logos-1.1.25-1
  • Chris PeBenito fe51b3
  • setup-2.5.37-1.1
  • Chris PeBenito fe51b3
  • basesystem-8.0-4
  • Chris PeBenito fe51b3
  • tzdata-2004e-2
  • Chris PeBenito fe51b3
  • glibc-2.3.4-2
  • Chris PeBenito fe51b3
  • beecrypt-3.1.0-6
  • Chris PeBenito fe51b3
  • chkconfig-1.3.11.2-1
  • Chris PeBenito fe51b3
  • e2fsprogs-1.35-11.6.EL4
  • Chris PeBenito fe51b3
  • ethtool-1.8-4
  • Chris PeBenito fe51b3
  • gdbm-1.8.0-24
  • Chris PeBenito fe51b3
  • iputils-20020927-16
  • Chris PeBenito fe51b3
  • libacl-2.2.23-5
  • Chris PeBenito fe51b3
  • libselinux-1.19.1-7
  • Chris PeBenito fe51b3
  • libstdc++-3.4.3-9.EL4
  • Chris PeBenito fe51b3
  • mingetty-1.07-3
  • Chris PeBenito fe51b3
  • bash-3.0-19.2
  • Chris PeBenito fe51b3
  • ncurses-5.4-13
  • Chris PeBenito fe51b3
  • net-tools-1.60-37
  • Chris PeBenito fe51b3
  • popt-1.9.1-7_nonptl
  • Chris PeBenito fe51b3
  • redhat-release-4AS-2
  • Chris PeBenito fe51b3
  • hotplug-2004_04_01-7.2
  • Chris PeBenito fe51b3
  • zlib-1.2.1.2-1
  • Chris PeBenito fe51b3
  • cpio-2.5-7.EL4.1
  • Chris PeBenito fe51b3
  • findutils-4.1.20-7
  • Chris PeBenito fe51b3
  • grep-2.5.1-31
  • Chris PeBenito fe51b3
  • grub-0.95-3.1
  • Chris PeBenito fe51b3
  • readline-4.3-13
  • Chris PeBenito fe51b3
  • rpm-libs-4.3.3-7_nonptl
  • Chris PeBenito fe51b3
  • shadow-utils-4.0.3-41.1
  • Chris PeBenito fe51b3
  • rpm-4.3.3-7_nonptl
  • Chris PeBenito fe51b3
  • tar-1.14-4
  • Chris PeBenito fe51b3
  • cracklib-dicts-2.7-29
  • Chris PeBenito fe51b3
  • policycoreutils-1.18.1-4
  • Chris PeBenito fe51b3
  • util-linux-2.12a-16.EL4.6
  • Chris PeBenito fe51b3
  • udev-039-10.8.EL4
  • Chris PeBenito fe51b3
  • initscripts-7.93.11.EL-1
  • Chris PeBenito fe51b3
  • mkinitrd-4.1.18-2
  • Chris PeBenito fe51b3
  • passwd-0.68-10
  • Chris PeBenito fe51b3
  • bzip2-1.0.2-13
  • Chris PeBenito fe51b3
  • logrotate-3.7.1-2
  • Chris PeBenito fe51b3
  • libxml2-2.6.16-6
  • Chris PeBenito fe51b3
  • make-3.80-5
  • Chris PeBenito fe51b3
  • iptables-1.2.11-3.1.RHEL4
  • Chris PeBenito fe51b3
  • vixie-cron-4.1-20_EL
  • Chris PeBenito fe51b3
  • comps-4AS-0.20050107
  • Chris PeBenito fe51b3