Gentoo Archives: gentoo-hardened

From: Petre Rodan <petre.rodan@××××××××××××.com>
To: gentoo-hardened@g.o
Cc: Tad <tadglines@×××××××.net>
Subject: Re: [gentoo-hardened] qmail on SElinux
Date: Thu, 27 Nov 2003 15:06:18
Message-Id: 20031127150616.GA1240@peter.rav.local
In Reply to: Re: [gentoo-hardened] qmail on SElinux by Wolfram Schlich
1 Ooops,
2
3 I've been playing too much with those .muttrc hooks ;)
4
5 sorry for the wrong From: header
6
7 bye,
8 peter
9
10 On Thu, Nov 27, 2003 at 04:55:39PM +0200, Wolfram Schlich wrote:
11 >
12 > Good evening,
13 >
14 > On Wed, Nov 26, 2003 at 05:38:45PM -0800, Tad wrote:
15 > > I'm working on creating policy files for daemontools, ucspi-tcp and qmail.
16 > >
17 > > There are already qmail.te and qmail.fc files available from the NSA's
18 > > policy-1.2, so I'll be using that as a base.
19 > >
20 > > Has anyone done this already, or maybe working on it? I don't want do
21 > > duplicate effort if I can avoid it.
22 > >
23 > > -Tad
24 > >
25 >
26 > have a look at
27 > http://team.rav.ro/peter/policy.tar.gz
28 >
29 > you'll find test policies for daemontools, clockspeed, publicfile and different MUAs.
30 > the qmail policy is the NSA one, but I had to make a few changes to it.
31 >
32 > the thing is these are only test policies, and they will definitely not work before you change them a little.
33 >
34 > I have left svc to run in the initrc_t context because I've felt that initrc's role is pretty much the same as the daemontools's one, so this inheritance can't hurt.
35 >
36 >
37 > bye,
38 > peter
39 >