1 |
The main aspect of this SELinux module consists in defining a new |
2 |
domain for the |
3 |
confinement of the PAMLDAP module. I have created this module as when |
4 |
I used the |
5 |
PamLDAP extension for remote authentications, I discovered that it used |
6 |
sensitive information for LDAP connexions. |
7 |
|
8 |
The module aims to protect these datas (security enhancement in order |
9 |
to prevent to prevent root services from accessing these previously |
10 |
etc_t labelled files). |
11 |
|
12 |
|
13 |
The informations are described in the gentoo bug 199561 |
14 |
(http://bugs.gentoo.org/show_bug.cgi?id=199561), with links to the |
15 |
SELinux module sources and documentations. |
16 |
|
17 |
Best regards. |
18 |
|
19 |
Julien Thomas |
20 |
|
21 |
-- |
22 |
gentoo-hardened@g.o mailing list |