Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] SELinux policy for heimdal with LDAP support
Date: Sat, 28 Jan 2006 17:32:22
Message-Id: 1138469364.31529.22.camel@gorn.pebenito.net
In Reply to: [gentoo-hardened] SELinux policy for heimdal with LDAP support by Mivz
1 On Wed, 2006-01-25 at 12:56 +0100, Mivz wrote:
2 > I would like some comment on the policy, what can I do better.
3 > Is this a odd or nonstandard daemon configuration, or could it be
4 > integrated in the portage tree?
5 > I would be interested in maintaining this policy my self.
6
7 If heimdal is supposed to work with LDAP, then its not nonstandard.
8 Nonstandard means moving file locations or gluing two programs together
9 that aren't normally associated with each other. As for the rules, they
10 seem reasonable except for the two rules I listed below, which are odd
11 since they deal with a user domain. It can't be integrated into portage
12 as we're working on switching over to reference policy [1], which has a
13 new organization.
14
15 [1] http://marc.theaimsgroup.com/?l=gentoo-hardened&m=113433863728029&w=2
16
17 > plain text document attachment (heimdal-LDAP.te)
18
19 > #/tmp/krb5cc
20 > allow user_t local_login_tmp_t:file { read lock append };
21 >
22 > #Needed for whoami / id to work. Else: "I have no name!" for ldap users.
23 > allow user_t nscd_var_run_t:dir search;
24
25 --
26 Chris PeBenito
27 <pebenito@g.o>
28 Developer,
29 Hardened Gentoo Linux
30 Embedded Gentoo Linux
31
32 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
33 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] SELinux policy for heimdal with LDAP support "Lamont R. Peterson" <lrp@××××××××.com>
Re: [gentoo-hardened] SELinux policy for heimdal with LDAP support Mivz <mivz@×××××××××××××.net>