WARNING - OLD ARCHIVES

This is an archived copy of the Xen.org mailing list, which we have preserved to ensure that existing links to archives are not broken. The live archive, which contains the latest emails, can be found at http://lists.xen.org/
   
 
 
Xen 
 
Home Products Support Community News
 
   
 

xen-users

[Xen-users] Different output for "xm getpolicy" and "xensec_tool getpoli

To: xen-users@xxxxxxxxxxxxxxxxxxx
Subject: [Xen-users] Different output for "xm getpolicy" and "xensec_tool getpolicy"
From: Yanjun Wu <yanjun.wu@xxxxxxxxx>
Date: Tue, 19 May 2009 17:36:03 +0800
Delivery-date: Tue, 19 May 2009 02:36:44 -0700
Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:date:message-id:subject :from:to:content-type:content-transfer-encoding; bh=EfeXt8LjIVV4xrJtdapeSj0i14TPC0aRGCRyk2uwS+k=; b=he+JFIRc0Hl6z13lgoTb+9wi/WsTzWmAmkmi/EoFs/ZQiRkOJvoVUVf5vSDd/FjVoT Kz5PC9InaCdPEq4RwsSFsa9el3Wt9LbKUMwP4NyVJrTbjUX2FNZOyiC4Lb7zGquSx9Qv /7yF+52FwNZDvnplogxYI2IbTBZlSut3ADOnY=
Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:content-type :content-transfer-encoding; b=leYROD+47DBlydcyZyzK2dgZRFZvKxGyt7R6q5ynN54FzPsprxK85e28IXmMmWnave A67w598WUvB2UfeNQxJjJwka4ZpC7P1/S0T0JnROXVSEemvdDlZpIH56tZW7FbBp7BcS 18IkhBbYMyrHJGBAmKc20jYUNJL/IBSDK8//g=
Envelope-to: www-data@xxxxxxxxxxxxxxxxxxx
List-help: <mailto:xen-users-request@lists.xensource.com?subject=help>
List-id: Xen user discussion <xen-users.lists.xensource.com>
List-post: <mailto:xen-users@lists.xensource.com>
List-subscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=subscribe>
List-unsubscribe: <http://lists.xensource.com/mailman/listinfo/xen-users>, <mailto:xen-users-request@lists.xensource.com?subject=unsubscribe>
Sender: xen-users-bounces@xxxxxxxxxxxxxxxxxxx
I use xen-3.3.1 and CentOS5.3 as dom0. After compiling and booting
with XSM and ACM enabled,  I ran "xm getpolicy" and got the following
output
[root@yanjun tools]# xm getpolicy
Supported security subsystems   : None

No policy is installed.

But when I use "xensec_tool getpolicy", it outputs:
[root@yanjun tools]# xensec_tool getpolicy

Policy dump:
============
POLICY REFERENCE = DEFAULT.
PolicyVer = 0.
XML Vers. = 0.0
Magic     = 1debc.
Len       = 9c.
Primary   = CHINESE WALL (c=1, off=4c).
Secondary = SIMPLE TYPE ENFORCEMENT (c=2, off=7c).


Chinese Wall policy:
====================
Policy version= 0.
Max Types     = 1.
Max Ssidrefs  = 2.
Max ConfSets  = 1.
Ssidrefs Off  = 24.
Conflicts Off = 28.
Runing T. Off = 2a.
C. Agg. Off   = 2c.

SSID To CHWALL-Type matrix:

   ssidref 0:  00
   ssidref 1:  00  <-- Domain-0

Confict Sets:

   c-set 0:    00

Running
Types:         00

Conflict
Aggregate Set: 00


Simple Type Enforcement policy:
===============================
Policy version= 0.
Max Types     = 2.
Max Ssidrefs  = 2.
Ssidrefs Off  = 14.

SSID To STE-Type matrix:

   ssidref 0: 00 01
   ssidref 1: 01 01  <-- Domain-0



I'm wondering why it is different. Could anyone give me a hint?

-- 
Yanjun Wu

_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users

<Prev in Thread] Current Thread [Next in Thread>
  • [Xen-users] Different output for "xm getpolicy" and "xensec_tool getpolicy", Yanjun Wu <=