1 |
On Wed, 2006-01-25 at 12:56 +0100, Mivz wrote: |
2 |
> I would like some comment on the policy, what can I do better. |
3 |
> Is this a odd or nonstandard daemon configuration, or could it be |
4 |
> integrated in the portage tree? |
5 |
> I would be interested in maintaining this policy my self. |
6 |
|
7 |
If heimdal is supposed to work with LDAP, then its not nonstandard. |
8 |
Nonstandard means moving file locations or gluing two programs together |
9 |
that aren't normally associated with each other. As for the rules, they |
10 |
seem reasonable except for the two rules I listed below, which are odd |
11 |
since they deal with a user domain. It can't be integrated into portage |
12 |
as we're working on switching over to reference policy [1], which has a |
13 |
new organization. |
14 |
|
15 |
[1] http://marc.theaimsgroup.com/?l=gentoo-hardened&m=113433863728029&w=2 |
16 |
|
17 |
> plain text document attachment (heimdal-LDAP.te) |
18 |
|
19 |
> #/tmp/krb5cc |
20 |
> allow user_t local_login_tmp_t:file { read lock append }; |
21 |
> |
22 |
> #Needed for whoami / id to work. Else: "I have no name!" for ldap users. |
23 |
> allow user_t nscd_var_run_t:dir search; |
24 |
|
25 |
-- |
26 |
Chris PeBenito |
27 |
<pebenito@g.o> |
28 |
Developer, |
29 |
Hardened Gentoo Linux |
30 |
Embedded Gentoo Linux |
31 |
|
32 |
Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243 |
33 |
Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243 |