Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] selinux 2006.1: semanage login has no effect
Date: Tue, 05 Dec 2006 04:04:04
Message-Id: 1165291134.4080.6.camel@gorn.pebenito.net
In Reply to: Re: [gentoo-hardened] selinux 2006.1: semanage login has no effect by panard@inzenet.org
1 On Mon, 2006-12-04 at 23:31 +0100, panard@×××××××.org wrote:
2 > Le lundi 4 décembre 2006 02:15, Chris PeBenito a écrit :
3 > > On Sun, 2006-12-03 at 11:19 +0100, Panard wrote:
4 > > > I followed the selinux 2006.1 upgrade guide.
5 > > >
6 > > > I would like to change my user 'panard' to staff_u.
7 > > > So I used the command
8 > > > semanage login -a -s staff_u panard
9 > > >
10 > > > and tried to login.
11 > > > But, my user is still in user_u context :
12 > > > panard@aragorn ~ $ id
13 > > > uid=1000(panard) gid=100(users) groupes=10(wheel),16(cron),35(games),81
14 > > > (apache),100(users),441(scanner) context=user_u:user_r:user_t
15 > >
16 > > Are you logging in locally, or over ssh?
17 > I tried both, giving the same result...
18 > I noticed that if I logged directly to root over ssh, the context is correct
19 > (root:staff_r:staff_t), but it doesn't work for any other users..
20
21 What versions of openssh, shadow, and pam do you have?
22
23 --
24 Chris PeBenito
25 <pebenito@g.o>
26 Developer,
27 Hardened Gentoo Linux
28
29 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
30 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] selinux 2006.1: semanage login has no effect Panard <panard@×××××××.org>