Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] SELinux - courier-imap
Date: Mon, 06 Aug 2007 13:49:49
Message-Id: 1186408084.4926.4.camel@defiant.pebenito.net
In Reply to: Re: [gentoo-hardened] SELinux - courier-imap by julien.thomas@enst-bretagne.fr
1 On Mon, 2007-08-06 at 12:05 +0200, julien.thomas@×××××××××××××.fr wrote:
2 > I knew (according to old posts on the list) that other people were
3 > interessted in these fixes, so the topic name modification !
4 >
5 > However, I still have a small problem that would prevent the whole
6 > thing from working :
7 >
8 > With shell operations like
9 > semanage fcontext -a -s system_u -t courier_var_run_t '/var/run/imapd.*'
10 > semanage fcontext -a -s system_u -t courier_var_run_t '/var/run/pop3.*'
11 > semanage fcontext -a -s system_u -t courier_authdaemon_var_run_t
12 > '/var/run/authdaemon?*
13 >
14 > and then a restorecon /var/run/*,
15 > the files are correctly labelled for courier-imap.
16 >
17 > But either when rebooting or after an unprecised amount of time (ie
18 > refreshing operations, maybe), the files are no more correctly
19 > labelled (var_run_t).
20 >
21 > So, it means that the daemons do not care about what I told and that
22 > they change the files type. How can this be fixed ?
23
24 Need files_pid_filetrans(courier_$1_t,courier_var_run_t,file) in the
25 template. Fedora doesn't need this, since they have a /var/run/courier
26 that is already courier_var_run_t.
27
28 --
29 Chris PeBenito
30 <pebenito@g.o>
31 Developer,
32 Hardened Gentoo Linux
33
34 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
35 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature