How come MCS Confinement is not working in SELinux even in enforcing mode?

    Date22 Sep 2015
    CategorySELinux
    1501
    Posted ByAnthony Pell

    MCS separation is a key feature in sVirt technology. We currently use it for separation of our Virtual machines using libvirt to launch vms with different MCS labels. SELinux sandbox relies on it to separate out its sandboxes. OpenShift relies on this technology for separating users, and now docker uses it to separate containers.

    When I discover a hammer, everything looks like a nail.

    You are not authorised to post comments.

    LinuxSecurity Poll

    In your opinion, what is the biggest advantage associated with choosing open-source software/products?

    Message!

    Poll results are hidden from public viewing.

    You are not authorized to vote on this poll.

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 4 answer(s).
    /component/communitypolls/?task=poll.vote
    8
    radio
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.