Skip to content
This repository has been archived by the owner on Sep 18, 2019. It is now read-only.

Transition to a different context when execusting binaries #4

Open
simo5 opened this issue Apr 21, 2017 · 0 comments
Open

Transition to a different context when execusting binaries #4

simo5 opened this issue Apr 21, 2017 · 0 comments

Comments

@simo5
Copy link
Member

simo5 commented Apr 21, 2017

When executing binaries like /usr/bin/pki we should transition to adifferent dopmain so rules like allow execmem are only given to the specific bianry and not necesary for the whole custodia process. In general this wil allow to restrict what can access ther nss databases too.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant