Gentoo Archives: gentoo-hardened

From: Sven Vermeulen <swift@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] SELinux base policy r2 in hardened-dev overlay
Date: Mon, 22 Aug 2011 18:19:30
Message-Id: 20110822181857.GB31692@gentoo.org
In Reply to: Re: [gentoo-hardened] SELinux base policy r2 in hardened-dev overlay by Matt Thode
1 On Mon, Aug 22, 2011 at 12:25:32PM -0500, Matt Thode wrote:
2 > I know this is not ideal, but can you simply allow sysadm_r to use rc-service and it's brothers?
3
4 Doesn't it already?
5
6 ~# id -Z
7 root:sysadm_r:sysadm_t
8
9 ~# rc-service postfix status
10 Authenticating root.
11 Password:
12 * status: started
13
14 Unless you mean to support it without asking for re-authentication. In that
15 case, check out bug #365761. It contains a "fix" for this if you prepend
16 your runscript activities with run_init. However, it seems not to support
17 the use of rc-service though.
18
19 Wkr,
20 Sven Vermeulen

Replies

Subject Author
Re: [gentoo-hardened] SELinux base policy r2 in hardened-dev overlay Matt Thode <mthode@××××××.org>