Gentoo Archives: gentoo-hardened

From: Petre Rodan <kaiowas@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] selinux maildir type?
Date: Wed, 13 Dec 2006 08:27:40
Message-Id: 20061213082605.GB7733@peter.bu.avira.com
In Reply to: [gentoo-hardened] selinux maildir type? by Justin Heesemann
1 Hi,
2
3 On Wed, Dec 13, 2006 at 09:07:01AM +0100, Justin Heesemann wrote:
4 > Hi..
5 > since I'm writing policies for dovecot and vpopmail, I was wondering if
6 > there's a special file context type for .maildir. At this time, with
7 > vpopmail being installed in /var/vpopmail the maildirectories get var_t so
8 > dovecot/vpopmail needs write, unlink... access to var_t:dir and var_t:file,
9 > which doesn't look to good for me :) but since i was unable to find anything
10 > about a qmail_maildir_t or anything like that..
11
12 the qmail policy expects maildirs to be labeled as {alias,user,staff,sysadm}_home_t
13
14 IIRC the maildirs for a virtual domain has to be kept in a directory that is the home of a unix user specialy created for this. so how about creating the virtual domain in /home/vpopmail and the rest will fix itself ?
15
16 also I clearly recall seeing a dovecot policy floating in modules/services, maybe it helps.
17
18 cheers,
19 peter
20
21 --
22 petre rodan
23 <kaiowas@g.o>
24 Developer,
25 Hardened Gentoo Linux