Re: [selinux] Allowing not sysadm_t access to change root password

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, Oct 17, 2011 at 04:55:50PM -0400, David A. Cafaro wrote:
> 
> Permissive mode reports no selinux errors and the password change
> works (I'm assuming that passwd is detecting permissive mode).

Make sure you have "semanage dontaudit off".

Also look for things besides AVCs; if you're grepping the audit log,
include SELINUX in what you check for.

-Robin

-- 
http://singinst.org/ :  Our last, best hope for a fantastic future.
Lojban (http://www.lojban.org/): The language in which "this parrot
is dead" is "ti poi spitaki cu morsi", but "this sentence is false"
is "na nei".   My personal page: http://www.digitalkingdom.org/rlp/
--
selinux mailing list
selinux@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/selinux


[Index of Archives]     [Fedora Users]     [Fedora Desktop]     [Big List of Linux Books]     [Yosemite News]     [Yosemite Campsites]     [KDE Users]     [Gnome Users]

  Powered by Linux