Gentoo Archives: gentoo-hardened

From: John Huttley <John@×××××××××××××××.nz>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] SELinux - courier-imap
Date: Fri, 03 Aug 2007 22:32:10
Message-Id: 46B3AC18.7030402@mib-infotech.co.nz
In Reply to: [gentoo-hardened] SELinux - courier-imap by julien.thomas@enst-bretagne.fr
1 I'm glad you are fixiing this since I'm using it as a basis for a new
2 cyrus-imapd policy!!
3
4 --john
5
6
7 julien.thomas@×××××××××××××.fr wrote:
8 > Hi.
9 > The problems of courier-imap began to be solved ...
10 >
11 > (The previous post where labelled by "SELinux - network streams" but
12 > as I am more focused with courier-imap now, I though it was good to
13 > change the subject)
14 >
15 > However, here is the problem I have with file labelling :
16 >
17 > I put it /etc/security/selinx/file_contexts the following lines
18 > /var/run/impad.* system_u:object_r:courier_var_run_t
19 > /var/run/pop3.* system_u:object_r:courier_var_run_t
20 > /var/run/authdaemon.* system_u:object_r:courier_var_run_t
21 >
22 > as the previous ones (/var/run/courier(/.*)?) where wrong.
23 >
24 > However, restorecon do not give the good contexts for these files
25 > (var_run_t). Besides, when the server are restarted or after let's say
26 > one hour,
27 > the files got the var_run_t context though I changed them with chcon.
28 >
29 > Where should I put this file_context information.
30 > (Do I have to add this I a QuickFix module ?)
31 >
32 > for the other problem, It was due to transition problems.
33 > I have added the following lines :
34 > type_transition initrc_t courier_exec_t:process courier_tcpd_t;
35 > type_transition courier_tcpd_t courier_authdaemon_exec_t:process
36 > courier_authdaemon_t;
37 >
38 > Julien Thomas.
39 >
40 --
41 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] SELinux - courier-imap julien.thomas@×××××××××××××.fr