Research Menu

.
Skip Search Box

SELinux Mailing List

SE Linux on Debian

From: Tracy R Reed <treed_at_ultraviolet.org>
Date: Tue, 1 Oct 2002 15:36:38 -0700


I am trying to get SE Linux working on my debian system. I've been running RedHat for years and I'm somewhat new to debian. :) I am running testing. I installed 2.4.19 and the lsm-new-2002082308-2.4.19.patch.12.gz with apt-get also. The kernel is running just fine. But I am having trouble with the policy and utils.

I installed the debs with apt-get from:

deb http://www.microcomaustralia.com.au/debian/ stable selinux

because that is what is in the topic on the IRC channel. Is it ok to install these from stable even though my distro is actually testing?

Here are the debs:

libselinux-dev
selinux
selinux-policy-default

But the new ps, ls, sshd, etc. do not seem to be included here. Where do I get those? Are they not in a deb?

When I installed the new policy it asked a lot of questions such as:

Setting up selinux-policy-default (2002082308-4.bam.1) ... File "domains/program/apache.te" changed. Copy/Ignore/Always ignore/view Diff [c/I/a/d]?

I said Copy to all of them. I'm not running all of that but I will be playing with various different things so I want the latest policies installed. When it was done asking questions I got this error:

/usr/sbin/checkpolicy: loading policy configuration from /etc/security/selinux/src/policy.conf

ERROR 'parse error' at token 'run_program' on line 71322: run_program(sysadm_t, sysadm_r, deb, dpkg_exec_t, dpkg_t) #
/usr/sbin/checkpolicy: error(s) encountered while parsing configuration
make: *** [/etc/security/selinux/policy.12] Error 1 dpkg: error processing selinux-policy-default (--configure):  subprocess post-installation script returned error exit status 2

Errors were encountered while processing:  selinux-policy-default
E: Sub-process /usr/bin/dpkg returned an error code (1)

Whenever I install a new package apt-get tries to recompile the policy (why?) and I get the same error.

Any help is greatly appreciated!

-- 
Tracy Reed      http://www.ultraviolet.org
"Our products just aren't engineered for security." - Brian Valentine, 
senior VP in charge of Microsoft's Windows development 5 Sept 2002

-- This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message.

  • application/pgp-signature attachment: stored
Received on Tue 1 Oct 2002 - 18:52:07 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service