Re: Openvz 8? [message #53737 is a reply to message #53734] |
Mon, 15 March 2021 17:00   |
khorenko
Messages: 533 Registered: January 2006 Location: Moscow, Russia
|
Senior Member |
|
|
Hi,
well, i did not have a chance to work under selinux code and not sure
1) for selinux management inside a VZ Container:
Is there is a functionality at the moment to configure selinux per-namespace from inside this namespace.
i have not seen such a functionality in mainstream kernel. If i miss something, please point me out.
2) for selinux configuration for VZ Containers done on host:
Well, this seems to be possible, why not,
the main difficulty here should be to audit all VZ userspace and generate a selinux configuration for each of them
which will be strict enough but won't break anything.
But you've meant the point 1), right?
And while there is no such a functionality available, it will be a big feature.
If your problem is solved - please, report it!
It's even more important than reporting the problem itself...
|
|
|