Gentoo Archives: gentoo-hardened

From: petre rodan <kaiowas@g.o>
To: Mark Huijgen <gentoo@×××××××.tk>
Cc: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] courier-imap avc denied name_bind
Date: Wed, 10 Nov 2004 17:34:16
Message-Id: 41924FBE.5080309@gentoo.org
In Reply to: [gentoo-hardened] courier-imap avc denied name_bind by Mark Huijgen
1 Hi,
2
3 Mark Huijgen wrote:
4 > With base-policy 20040906 and courier-imap-20040928
5 >
6 > avc: denied { name_bind } for pid=1238
7 > exe=/usr/lib/courier-imap/couriertcpd
8 > scontext=system_u:system_r:courier_tcpd_t
9 > tcontext=system_u:object_r:port_t tclass=tcp_socket
10 >
11 > When starting the imapd server of courier-imap.
12 > I think the reason for this is coming from courier-imap.te
13 > line 105-108
14 >
15 > allow courier_tcpd_t imap_port_t:tcp_socket name_bind;
16 > ...imaps_port_t...
17 > ...pop_port_t...
18 > ...pops_port_t...
19 >
20 > But these port types aren't defined in the policy.
21 > In net_contexts there are some for pop, but they are inside a
22 > ifdef('use_pop', and these are also not working for courier.
23 >
24 > I've tested it for the normal imap port, it works when i add this line
25 > to net_contexts:
26 > portcon tcp 143 system_u:object_r:imap_port_t
27 > it works fine.
28 >
29 > I think the same goes for 993 for imaps, 110 for pop and 995 for pops.
30
31 thanks for pointing that out.
32 'network hook'-related fixes are on my agenda for next week.
33
34 bye,
35 peter
36
37 --
38 petre rodan
39 <kaiowas@g.o>
40 Developer,
41 Hardened Gentoo Linux

Attachments

File name MIME type
signature.asc application/pgp-signature