1 |
I just committed app-admin/setools, and it should be hitting rsync by |
2 |
the time you read this. It is a set of graphical tools for managing |
3 |
SELinux policy. It does require X, but does not have to be installed on |
4 |
a SELinux machine. So you can copy your policy over to your workstation |
5 |
and edit and analyze it. If you install it on a selinux machine, there |
6 |
is a tool (seuser) for managing users, and keeping the selinux and unix |
7 |
user consistent. I dont have X on my test box, so I had to set up a |
8 |
fake policy to test this out, so its not well tested. |
9 |
|
10 |
There is an issue with the policy analyzer (apol) where it complains |
11 |
about var_run_lpd_t not being a type. Apol doesnt handle type aliases |
12 |
(var_run_lpd_t is an alias of lpd_var_run_t). I removed all the aliases |
13 |
from the selinux-base-policy. The next base-policy release will be |
14 |
soon, pending the closing of two open bugs. If you cant wait, I'll be |
15 |
releasing another cvs base-policy snapshot later today with the removed |
16 |
aliases. If you just want to fix your own policy, replace all of the |
17 |
instances var_run_lpd_t with lpd_var_run_t in your policy. |
18 |
|
19 |
-- |
20 |
Chris PeBenito |
21 |
<pebenito@g.o> |
22 |
Developer, SELinux |
23 |
Hardened Gentoo Linux |
24 |
|
25 |
Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243 |
26 |
Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243 |