Re: Selinux in enforcing mode prevent network interface to be configured at boot for Debian stable ( 5.0)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Justin P. Mattock wrote:
> if nothing the do a
> sudo /usr/sbin/semodule -DB
> (reboot)
> then what does audit2allow say?
> should give you some allow rules
> if so add them to your policy.

This will most likely output a very large number of rules that don't
make sense, ie. they would do more bad than good.

The basic problem is that the network scripts don't have their own
restricted domain in which they could run. Running them from udev on
'network hotplug event' will copy the udev context, which doesn't have
enough privileges to configure network. Giving these privileges to udev
directly would be sub-optimal.

Michal Svoboda

Attachment: pgpH8l2FaGotI.pgp
Description: PGP signature


[Index of Archives]     [Selinux Refpolicy]     [Linux SGX]     [Fedora Users]     [Fedora Desktop]     [Yosemite Photos]     [Yosemite Camping]     [Yosemite Campsites]     [KDE Users]     [Gnome Users]

  Powered by Linux