Re: pam_selinux and systemd

2017-09-07 Thread Dominick Grift
uirements are generally pretty simple: its used to > > > > > > > associate a context with a login shell. > > > > > > > > > > > > > > With systemd things have becomes a bit more complicated. > > > > > > > > >

Re: pam_selinux and systemd

2017-09-07 Thread Dominick Grift
ext with a login shell. > > > > > > > > > > > > With systemd things have becomes a bit more complicated. > > > > > > > > > > > > systemd uses pam_selinux to associate a context with both a login > > > > > >

Re: pam_selinux and systemd

2017-09-07 Thread Dominick Grift
; > > On Thu, 2017-09-07 at 11:05 +0200, Dominick Grift wrote: > > > > > pam_selinux requirements are generally pretty simple: its used to > > > > > associate a context with a login shell. > > > > > > > > > > With systemd things have

Re: pam_selinux and systemd

2017-09-07 Thread Dominick Grift
> pam_selinux requirements are generally pretty simple: its used to > > > > associate a context with a login shell. > > > > > > > > With systemd things have becomes a bit more complicated. > > > > > > > > systemd uses pam_selinux to

Re: pam_selinux and systemd

2017-09-07 Thread Dominick Grift
t; > associate a context with a login shell. > > > > > > With systemd things have becomes a bit more complicated. > > > > > > systemd uses pam_selinux to associate a context with both a login > > > shell (via container-shell@.service) as well as with a syst

Re: pam_selinux and systemd

2017-09-07 Thread Dominick Grift
ngs have becomes a bit more complicated. > > > > systemd uses pam_selinux to associate a context with both a login > > shell (via container-shell@.service) as well as with a systemd --user > > instance. > > > > Ideally one would not associate a login shell cont

Re: pam_selinux and systemd

2017-09-07 Thread Stephen Smalley
On Thu, 2017-09-07 at 11:05 +0200, Dominick Grift wrote: > pam_selinux requirements are generally pretty simple: its used to > associate a context with a login shell. > > With systemd things have becomes a bit more complicated. > > systemd uses pam_selinux to associate a

pam_selinux and systemd

2017-09-07 Thread Dominick Grift
pam_selinux requirements are generally pretty simple: its used to associate a context with a login shell. With systemd things have becomes a bit more complicated. systemd uses pam_selinux to associate a context with both a login shell (via container-shell@.service) as well as with a systemd