Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: gentoo-hardened@l.g.o
Subject: RE: [gentoo-hardened] Mislabeled root home directory
Date: Mon, 18 Aug 2008 13:02:23
Message-Id: 1219064525.5102.4.camel@defiant.pebenito.net
In Reply to: RE: [gentoo-hardened] Mislabeled root home directory by Randy Tupas
1 On Sat, 2008-08-09 at 13:13 -0400, Randy Tupas wrote:
2 > I am using the targeted policy.
3 >
4 > The ebuild version of policycoreutils is 1.34.15.
5 >
6 > "restorecon /root" does not fix the problem.
7 >
8
9 Try applying the attached patch to your genhomedircon. Then rebuild
10 policy with 'semodule -B', then try the restorecon again.
11
12
13 > ----------------------------------------
14 > > Subject: Re: [gentoo-hardened] Mislabeled root home directory
15 > > From: pebenito@g.o
16 > > To: gentoo-hardened@l.g.o
17 > > Date: Mon, 4 Aug 2008 15:33:58 -0400
18 > >
19 > > On Fri, 2008-08-01 at 22:35 -0400, Randy Tupas wrote:
20 > >> I recently updated to the 20080525 selinux base policy and modules.
21 > >> I've received the following avc messages:
22 > >>
23 > >> Aug 01 18:53:22 tux (null): avc: denied pid=8004 comm=ssmtp name=root
24 > >> ino=87746 dev=sdb3 scontext=system_u:system_r:system_mail_t
25 > >> tcontext=system_u:object_r:default_t tclass=dir
26 > >>
27 > >> A little searching revealed that the root home directory, /root, has
28 > >> the following context:
29 > >>
30 > >> system_u:object_r:default_t
31 > >
32 > > Need more information. Which policy (strict or targeted)? Also, what
33 > > is the version of your policycoreutils? If you do `restorecon /root`
34 > > does it get fixed?
35 > >
36 > >> I'm sure this is in error - but wanted to make sure. I believe the
37 > >> problem lies with the following line
38 > >> in /etc/selinux/targeted/context/files/file_contexts:
39 > >>
40 > >> /root/\.default_contexts -- system_u:object_r:default_context_t
41 > >
42 > > No, its not.
43 > >
44 > >
45 > > --
46 > > Chris PeBenito
47 > >
48 > > Developer,
49 > > Hardened Gentoo Linux
50 > >
51 > > Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
52 > > Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243
53 >
54 > _________________________________________________________________
55 > Get more from your digital life. Find out how.
56 > http://www.windowslive.com/default.html?ocid=TXT_TAGLM_WL_Home2_082008
57 --
58 Chris PeBenito
59 <pebenito@g.o>
60 Developer,
61 Hardened Gentoo Linux
62
63 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
64 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
policycoreutils-stable.diff text/plain
signature.asc application/pgp-signature