1 |
On Mon, 2007-11-19 at 01:13 +0100, julien.thomas@×××××××××××××.fr wrote: |
2 |
> The main aspect of this SELinux module consists in defining a new |
3 |
> domain for the |
4 |
> confinement of the PAMLDAP module. I have created this module as when |
5 |
> I used the |
6 |
> PamLDAP extension for remote authentications, I discovered that it used |
7 |
> sensitive information for LDAP connexions. |
8 |
> |
9 |
> The module aims to protect these datas (security enhancement in order |
10 |
> to prevent to prevent root services from accessing these previously |
11 |
> etc_t labelled files). |
12 |
|
13 |
Thanks for your submission. I especially appreciate the design document |
14 |
you wrote. However, I don't think this particular action is required, |
15 |
but another. |
16 |
|
17 |
First, the specified domains already have access to etc_t, so these |
18 |
rules are redundant. You suggest adding a type for the ldap.conf |
19 |
because it has authentication data, which I agree with. However, the |
20 |
ldap policy already has a type which might be appropriate for this file, |
21 |
slapd_etc_t. |
22 |
|
23 |
As for the style, the reference policy style is preferred. Please see |
24 |
the website [1] for more details. |
25 |
|
26 |
[1] http://oss.tresys.com/projects/refpolicy/wiki/GettingStarted |
27 |
|
28 |
-- |
29 |
Chris PeBenito |
30 |
<pebenito@g.o> |
31 |
Developer, |
32 |
Hardened Gentoo Linux |
33 |
|
34 |
Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243 |
35 |
Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243 |