1 |
On Sat, 2008-08-09 at 13:13 -0400, Randy Tupas wrote: |
2 |
> I am using the targeted policy. |
3 |
> |
4 |
> The ebuild version of policycoreutils is 1.34.15. |
5 |
> |
6 |
> "restorecon /root" does not fix the problem. |
7 |
> |
8 |
|
9 |
Try applying the attached patch to your genhomedircon. Then rebuild |
10 |
policy with 'semodule -B', then try the restorecon again. |
11 |
|
12 |
|
13 |
> ---------------------------------------- |
14 |
> > Subject: Re: [gentoo-hardened] Mislabeled root home directory |
15 |
> > From: pebenito@g.o |
16 |
> > To: gentoo-hardened@l.g.o |
17 |
> > Date: Mon, 4 Aug 2008 15:33:58 -0400 |
18 |
> > |
19 |
> > On Fri, 2008-08-01 at 22:35 -0400, Randy Tupas wrote: |
20 |
> >> I recently updated to the 20080525 selinux base policy and modules. |
21 |
> >> I've received the following avc messages: |
22 |
> >> |
23 |
> >> Aug 01 18:53:22 tux (null): avc: denied pid=8004 comm=ssmtp name=root |
24 |
> >> ino=87746 dev=sdb3 scontext=system_u:system_r:system_mail_t |
25 |
> >> tcontext=system_u:object_r:default_t tclass=dir |
26 |
> >> |
27 |
> >> A little searching revealed that the root home directory, /root, has |
28 |
> >> the following context: |
29 |
> >> |
30 |
> >> system_u:object_r:default_t |
31 |
> > |
32 |
> > Need more information. Which policy (strict or targeted)? Also, what |
33 |
> > is the version of your policycoreutils? If you do `restorecon /root` |
34 |
> > does it get fixed? |
35 |
> > |
36 |
> >> I'm sure this is in error - but wanted to make sure. I believe the |
37 |
> >> problem lies with the following line |
38 |
> >> in /etc/selinux/targeted/context/files/file_contexts: |
39 |
> >> |
40 |
> >> /root/\.default_contexts -- system_u:object_r:default_context_t |
41 |
> > |
42 |
> > No, its not. |
43 |
> > |
44 |
> > |
45 |
> > -- |
46 |
> > Chris PeBenito |
47 |
> > |
48 |
> > Developer, |
49 |
> > Hardened Gentoo Linux |
50 |
> > |
51 |
> > Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243 |
52 |
> > Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243 |
53 |
> |
54 |
> _________________________________________________________________ |
55 |
> Get more from your digital life. Find out how. |
56 |
> http://www.windowslive.com/default.html?ocid=TXT_TAGLM_WL_Home2_082008 |
57 |
-- |
58 |
Chris PeBenito |
59 |
<pebenito@g.o> |
60 |
Developer, |
61 |
Hardened Gentoo Linux |
62 |
|
63 |
Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243 |
64 |
Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243 |