Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Thoughts on these AVC denials
Date: Wed, 24 Oct 2012 15:02:23
Message-Id: 20121024144621.GA19728@gentoo.org
In Reply to: [gentoo-hardened] Thoughts on these AVC denials by Stan Sander
1 On Tue, Oct 23, 2012 at 12:50:22PM -0600, Stan Sander wrote:
2 > This is the invalid context that I think I need to address:
3 >
4 > Oct 23 11:47:21 iax kernel: type=1401 audit(1351014441.497:8823983):
5 > security_compute_sid: invalid context stan:system_r:initrc_t for
6 > scontext=stan:sysadm_r:sysadm_t
7 > tcontext=system_u:object_r:asterisk_initrc_exec_t tclass=process
8 >
9
10 Meh,
11
12 Seems my reply didn't hit the list first.
13
14 You probably forgot to add in the system_r role to the SELinux user, see
15 http://www.gentoo.org/proj/en/hardened/selinux/selinux-handbook.xml?part=2&chap=1#serviceadmin
16
17 Wkr,
18 Sven Vermeulen

Replies

Subject Author
Re: [gentoo-hardened] Thoughts on these AVC denials Stan Sander <stsander@×××××.net>