Gentoo Archives: gentoo-hardened

From: Mike Edenfield <kutulu@××××××.org>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] daemons not running in assigned domains
Date: Tue, 31 Jul 2007 02:51:37
Message-Id: 46AEA2C8.9020701@kutulu.org
In Reply to: [gentoo-hardened] daemons not running in assigned domains by John Huttley
1 John Huttley wrote:
2 > Hi,
3 > I've had a situation where most of my daemons were running in the
4 > initrc_t domain.
5 > Although the correct selinux-* packages were emerged, the polices were
6 > not loaded, due to issues with the base policy.
7 >
8 >
9 > I've reemerged the affected packages and that seems to fix the problem.
10 >
11 > Is this a general truth? The selinux-xx policy must be emerged,
12 > installed and running ./before/ emerging the xx package?
13
14 I think this is true, that the policy should be in place
15 before the package is installed. This way, all of the file
16 contexts and type rules are in place before the binaries are
17 installed and launched.
18
19 However, if you have "selinux" in your USE flags, portage
20 should pick up the proper policy packages and emerge them,
21 in the right order, automatically.
22
23 --
24 -- Mike
25
26 Still using IE? Get Firefox!
27 http://www.spreadfirefox.com/?q=affiliates&id=6492&t=1
28 --
29 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] daemons not running in assigned domains John Huttley <John@×××××××××××××××.nz>