Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: Ed Wildgoose <lists@××××××××××.com>
Cc: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Can't log into my selinux system
Date: Fri, 30 Apr 2004 00:27:05
Message-Id: 1083284820.26433.19.camel@gorn.pebenito.net
In Reply to: Re: [gentoo-hardened] Can't log into my selinux system by Ed Wildgoose
1 On Thu, 2004-04-29 at 17:18, Ed Wildgoose wrote:
2 > Thanks for your endless patience! Rebuilding baselayout does indeed
3 > seem to have allowed the policy to auto-load, and I can now log in via
4 > console and ssh!! Wahoo
5
6 Excellent!
7
8 > I guess the next steps are to start playing with it. I'm a bit hesitant
9 > about how to proceed though. There are clearly loads of access
10 [cut]
11 > lots of processes want urandom and cant have it
12
13 This is a known issue with having ssp in glibc.
14
15 > with mount not being able to access /etc/fstab I think?
16
17 I'd need to see the denial.
18
19 > What about things which look a little broken, eg emerging gpm and
20 > selinux-gpm stops my policy compiling with something about ps_aux
21 > (from memory) not being valid/defined. Is this a bug, or just
22 > something I read the docs about and fix..?
23
24 I need to update the gpm policy.
25
26 > I can't help feeling that I haven't done the required reading to even
27 > get started with selinux, but I'm not sure where to find the quickstart
28 > guide?
29
30 Well the quickstart guide here is for converting over to SELinux. I
31 have a policy overview which covers a lot of the main SELinux concepts.
32
33 http://www.gentoo.org/proj/en/hardened/selinux/selinux-policy.xml
34
35 --
36 Chris PeBenito
37 <pebenito@g.o>
38 Developer,
39 Hardened Gentoo Linux
40 Embedded Gentoo Linux
41
42 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
43 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature