Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Mislabeled root home directory
Date: Mon, 04 Aug 2008 19:34:11
Message-Id: 1217878438.4918.40.camel@defiant.pebenito.net
In Reply to: [gentoo-hardened] Mislabeled root home directory by Randy Tupas
1 On Fri, 2008-08-01 at 22:35 -0400, Randy Tupas wrote:
2 > I recently updated to the 20080525 selinux base policy and modules.
3 > I've received the following avc messages:
4 >
5 > Aug 01 18:53:22 tux (null): avc: denied pid=8004 comm=ssmtp name=root
6 > ino=87746 dev=sdb3 scontext=system_u:system_r:system_mail_t
7 > tcontext=system_u:object_r:default_t tclass=dir
8 >
9 > A little searching revealed that the root home directory, /root, has
10 > the following context:
11 >
12 > system_u:object_r:default_t
13
14 Need more information. Which policy (strict or targeted)? Also, what
15 is the version of your policycoreutils? If you do `restorecon /root`
16 does it get fixed?
17
18 > I'm sure this is in error - but wanted to make sure. I believe the
19 > problem lies with the following line
20 > in /etc/selinux/targeted/context/files/file_contexts:
21 >
22 > /root/\.default_contexts -- system_u:object_r:default_context_t
23
24 No, its not.
25
26
27 --
28 Chris PeBenito
29 <pebenito@g.o>
30 Developer,
31 Hardened Gentoo Linux
32
33 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
34 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
RE: [gentoo-hardened] Mislabeled root home directory Randy Tupas <rjtupas@×××××××.com>