[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Xen-users] Different output for "xm getpolicy" and "xensec_tool getpolicy"


  • To: xen-users@xxxxxxxxxxxxxxxxxxx
  • From: Yanjun Wu <yanjun.wu@xxxxxxxxx>
  • Date: Tue, 19 May 2009 17:36:03 +0800
  • Delivery-date: Tue, 19 May 2009 02:36:44 -0700
  • Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:content-type :content-transfer-encoding; b=leYROD+47DBlydcyZyzK2dgZRFZvKxGyt7R6q5ynN54FzPsprxK85e28IXmMmWnave A67w598WUvB2UfeNQxJjJwka4ZpC7P1/S0T0JnROXVSEemvdDlZpIH56tZW7FbBp7BcS 18IkhBbYMyrHJGBAmKc20jYUNJL/IBSDK8//g=
  • List-id: Xen user discussion <xen-users.lists.xensource.com>

I use xen-3.3.1 and CentOS5.3 as dom0. After compiling and booting
with XSM and ACM enabled,  I ran "xm getpolicy" and got the following
output
[root@yanjun tools]# xm getpolicy
Supported security subsystems   : None

No policy is installed.

But when I use "xensec_tool getpolicy", it outputs:
[root@yanjun tools]# xensec_tool getpolicy

Policy dump:
============
POLICY REFERENCE = DEFAULT.
PolicyVer = 0.
XML Vers. = 0.0
Magic     = 1debc.
Len       = 9c.
Primary   = CHINESE WALL (c=1, off=4c).
Secondary = SIMPLE TYPE ENFORCEMENT (c=2, off=7c).


Chinese Wall policy:
====================
Policy version= 0.
Max Types     = 1.
Max Ssidrefs  = 2.
Max ConfSets  = 1.
Ssidrefs Off  = 24.
Conflicts Off = 28.
Runing T. Off = 2a.
C. Agg. Off   = 2c.

SSID To CHWALL-Type matrix:

   ssidref 0:  00
   ssidref 1:  00  <-- Domain-0

Confict Sets:

   c-set 0:    00

Running
Types:         00

Conflict
Aggregate Set: 00


Simple Type Enforcement policy:
===============================
Policy version= 0.
Max Types     = 2.
Max Ssidrefs  = 2.
Ssidrefs Off  = 14.

SSID To STE-Type matrix:

   ssidref 0: 00 01
   ssidref 1: 01 01  <-- Domain-0



I'm wondering why it is different. Could anyone give me a hint?

-- 
Yanjun Wu

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users


 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.