Gentoo Archives: gentoo-hardened

From: Alain Toussaint <alain.toussaint@××××××××.ca>
To: gentoo-hardened@l.g.o
Subject: RE: [gentoo-hardened] permission problem in /etc
Date: Tue, 13 Mar 2012 00:16:26
Message-Id: 34046447cdedd58ef825fe1f05811fe6@mail.gmail.com
In Reply to: Re: [gentoo-hardened] permission problem in /etc by Sven Vermeulen
1 > > Pardon me for the dumb question but I'm having a migraine and must
2 > prepare
3 > > for a midterm tomorrow;
4 > >
5 > > > allow dovecot_t dovecot_etc_t:file read_file_perms;
6 > >
7 > > How do I do that? :)
8 >
9 >
10 > Hmm either I forgot to reply, or the reply didn't reach my mailbox, so
11 > here
12 > goes the answer ;-)
13 >
14 > http://www.gentoo.org/proj/en/hardened/selinux-faq.xml#localpolicy
15 >
16 > In short, you'll need to create a policy file, build it and include it
17 in
18 > the system. The policy will be inserted in the policy store so that it
19 is
20 > loaded every time you (re)boot the system, so you can remove the source
21 > file
22 > if you want.
23 >
24 > Usually you don't want to though. I personally have a single
25 > "localpolicy.te" file in which I put all my exceptional rules (that
26 don't
27 > need to be part of the main policy, but are necessary on my system) and
28 > maintain that file.
29
30 In the end, this is no longer apropos (for now) because I transferred all
31 my mail setup to google apps for business but I got a new spare computer
32 which I will use for R&D of a numbers of projects including developing
33 policy files for selinux.
34
35 Do you have some project for which I could help develop policy files? This
36 will be a good way for me to learn selinux.
37
38 Alain

Replies

Subject Author
Re: [gentoo-hardened] permission problem in /etc Sven Vermeulen <swift@g.o>