Ignacio Vazquez-Abrams wrote: >On Mon, 2005-03-14 at 11:47 -0500, James B. Byrne wrote: > > >>allow httpd_t var_log_t:file { append read write }; >>allow mailman_cgi_t file_t:dir search; >>Nuh uh. These permissions are WAY too broad. Log this in the CentOS bug >>tracker. >> >> Yes, you are right. It allows mailman cgis to search all the directories with enough permission in the DAC space. Hmm. A bug in audit2allow? I think it would be enough to allow mailman to search the mailman related dirs and files. bye, Ago