Research Menu

.
Skip Search Box

SELinux Mailing List

Logrotate, ssh_agent - read selinux_config_t

From: Ivan Gyurdiev <ivg2_at_cornell.edu>
Date: Thu, 31 Mar 2005 14:06:15 -0500


logrotate and ssh_agent try to read /etc/selinux/config and fail. I thought it would be reasonable to allow that, but I see this:

apache_macros.te:dontaudit httpd_$1_script_t selinux_config_t:dir search;
crontab_macros.te:dontaudit $1_crontab_t selinux_config_t:dir search; inetd_macros.te:dontaudit $1_t selinux_config_t:dir search; ssh_agent_macros.te:dontaudit $1_ssh_agent_t selinux_config_t:dir search;
ssh_macros.te:dontaudit $1_ssh_keysign_t selinux_config_t:dir search; xserver_macros.te:dontaudit $1_xserver_t selinux_config_t:dir search;

Why?

--

Ivan Gyurdiev <ivg2@cornell.edu>
Cornell University

--

This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message. Received on Thu 31 Mar 2005 - 14:01:31 EST

 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service