RE: SELinux Policy in OpenSUSE 11.2

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Justin, could you share what you did to reach that state?  Your last email yesterday left me with the impression that you were rebuilding some tools from source...  What tools, what versions?  What booleans did you disable?

-----Original Message-----
From: Justin P. mattock [mailto:justinmattock@xxxxxxxxx] 
Sent: Thursday, February 18, 2010 4:40 PM
To: Alan Rouse
Cc: Stephen Smalley; Dominick Grift; 'selinux@xxxxxxxxxxxxx'
Subject: Re: SELinux Policy in OpenSUSE 11.2

alright... policy is up and running
in full enforcement mode:

SELinux status:                 enabled
SELinuxfs mount:                /selinux
Current mode:                   enforcing
Mode from config file:          error (Permission denied)
Policy version:                 24
Policy from config file:        targeted

Process contexts:
Current context:                name:user_r:user_t
Init context:                   unknown (Permission denied)

File contexts:
Controlling term:               name:object_r:user_devpts_t
/etc/passwd                     system_u:object_r:etc_t
/bin/bash                       system_u:object_r:shell_exec_t
/bin/login                      system_u:object_r:login_exec_t
/bin/sh                         system_u:object_r:bin_t ->
system_u:object_r:shell_exec_t
/sbin/agetty                    system_u:object_r:getty_exec_t
/sbin/mingetty                  system_u:object_r:getty_exec_t
/lib/libc.so.6                  system_u:object_r:lib_t ->
system_u:object_r:lib_t
/lib/ld-linux.so.2              system_u:object_r:lib_t ->
system_u:object_r:ld_so_t



I tried to enable poly-instantiation support(pam_namespace), but need to look more into that because I never really set it up with gdm.

Anyways I'm able to boot up, able to
use firefox and evolution. as for anything else I'm sure just need to define the allow rules.


Now the only real area of interest is
the dbus message pointing to targeted.

I'm guessing dbus was built with a hard wire, if so this would require rebuilding dbus, or using anther rpm package built correctly.
(if possible without breaking the system dependencies).

but then again it could be just a boolean.
In any case main thing is full enforcement works gdm works, nice system I'd have to say.



Justin P. Mattock


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@xxxxxxxxxxxxx with
the words "unsubscribe selinux" without quotes as the message.

[Index of Archives]     [Selinux Refpolicy]     [Linux SGX]     [Fedora Users]     [Fedora Desktop]     [Yosemite Photos]     [Yosemite Camping]     [Yosemite Campsites]     [KDE Users]     [Gnome Users]

  Powered by Linux