Hi there, Recently I started reading of selinux and I find it very useful. I'm planing to use it for a multiuser server installation during the next 6 months. I've read most of the documents I could find and a large portion of the 'SELinux by Example' book. No matter where I looked I did not find an answer to the following question: When using the refpolicy, is it possible to adjust permissions without changing the existing modules? As far as I understand, the proper way to perform changes to existing modules is to change the appropriate .te file and recompile it, but this presumes that there is only one kind of policy, one policy tree and no future upgrades. Should I create my own supplementary modules without defining any interfaces and load them? -- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.