Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] SELinux module proposal for pamldap
Date: Wed, 28 Nov 2007 14:28:40
Message-Id: 1196259977.4635.13.camel@defiant.pebenito.net
In Reply to: [gentoo-hardened] SELinux module proposal for pamldap by julien.thomas@enst-bretagne.fr
1 On Mon, 2007-11-19 at 01:13 +0100, julien.thomas@×××××××××××××.fr wrote:
2 > The main aspect of this SELinux module consists in defining a new
3 > domain for the
4 > confinement of the PAMLDAP module. I have created this module as when
5 > I used the
6 > PamLDAP extension for remote authentications, I discovered that it used
7 > sensitive information for LDAP connexions.
8 >
9 > The module aims to protect these datas (security enhancement in order
10 > to prevent to prevent root services from accessing these previously
11 > etc_t labelled files).
12
13 Thanks for your submission. I especially appreciate the design document
14 you wrote. However, I don't think this particular action is required,
15 but another.
16
17 First, the specified domains already have access to etc_t, so these
18 rules are redundant. You suggest adding a type for the ldap.conf
19 because it has authentication data, which I agree with. However, the
20 ldap policy already has a type which might be appropriate for this file,
21 slapd_etc_t.
22
23 As for the style, the reference policy style is preferred. Please see
24 the website [1] for more details.
25
26 [1] http://oss.tresys.com/projects/refpolicy/wiki/GettingStarted
27
28 --
29 Chris PeBenito
30 <pebenito@g.o>
31 Developer,
32 Hardened Gentoo Linux
33
34 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
35 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] SELinux module proposal for pamldap Julien Thomas <julien.thomas@×××××××××××××.fr>