1 |
On Sat, Nov 12, 2016 at 10:45 AM, Robert Sharp |
2 |
<selinux@×××××××××××××××.org> wrote: |
3 |
> |
4 |
> There does not appear to be any specific rsyslog selinux package so I assume |
5 |
> it should all be syslog-related and already in the core policy (although I |
6 |
> cannot find it there). I also note that Red Hat has a page on setting up |
7 |
> Rsyslog in SELinux so I feel fairly sure it should work. It only tells you |
8 |
> how to change the ports, however. I am using TCP on port 514 but I don't |
9 |
> think I need to do anything according to RH. |
10 |
> |
11 |
> Have I missed something, done something fundamentally wrong, or just need to |
12 |
> add something to stop the AVCs? Not keen on blindly fixing things so I want |
13 |
> to know what I need to do and why before I do it. |
14 |
> |
15 |
> Thanks in anticipation, |
16 |
> Robert Sharp |
17 |
|
18 |
If there is no policy package installed and there is not one in the |
19 |
tree, you are on your own until one is written. I would double check |
20 |
to ensure one exists because: 1) To the best of my knowledge, there |
21 |
are logging policies available, and 2) policy packages tend to be |
22 |
missing from DEPENDS/RDEPENDS for things in the tree on SELinux |
23 |
profiles. |
24 |
|
25 |
As for where is best to ask, I would recommend #gentoo-hardened for |
26 |
this type of question. If you have a very detailed question it is |
27 |
likely you will get a better response on the mailing list though most |
28 |
of the frequent/knowledgeable posters idle in the aforementioned IRC |
29 |
channel. |
30 |
|
31 |
The SELinux portion of the Gentoo Project's wiki has received a lot of |
32 |
development by Swift(?). I would strongly recommend reading it. It |
33 |
will show you the discrepancies between RedHat SELinux administration |
34 |
and Gentoo SELinux administration (nothing is different except |
35 |
everything). |