Research
.
Skip Search Box

SELinux Mailing List

policy for afs server (v2)

From: selinux_at_reisse.net
Date: Thu, 28 Apr 2005 19:15:20 -0400

Here is a policy for an afs fileserver, with changes suggested by James Carter and Russel Coker.

Changes from James and Russel's version:

-Use domain names that match the executables.
-Don't grant write access to afs_config_t to all servers.
-Move the dontaudit rules to the afs_server_domain macro.


Only bosserver, fileserver, volserver, salvager, kaserver, vlserver, and ptserver processes are supported. Labelling rules are included only for the "traditional" (/usr/afs) layout; sites using the "openafs" layout will need different labelling rules.

The types defined for the kaserver ports may conflict with policies for other kerberos servers. Also, the policy has never been used during the installation and configuration of a server.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  • text/plain attachment: afs.te
  • text/plain attachment: afs.fc
Received on Thu 28 Apr 2005 - 19:14:10 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service