Research Menu

.
Skip Search Box

SELinux Mailing List

nagios changes

From: dwalsh_at_redhat.com
Date: Wed, 30 May 2007 10:43:53 -0400


nagios is designed to connect to all ports needs to read random data
Uses nsswitch

  • nsaserefpolicy/policy/modules/services/nagios.te 2007-05-29 14:10:57.000000000 -0400 +++ serefpolicy-3.0.1/policy/modules/services/nagios.te 2007-05-30 07:35:54.000000000 -0400 @@ -73,8 +73,10 @@ corenet_udp_sendrecv_all_nodes(nagios_t) corenet_tcp_sendrecv_all_ports(nagios_t) corenet_udp_sendrecv_all_ports(nagios_t) +corenet_tcp_connect_all_ports(nagios_t)

 dev_read_sysfs(nagios_t)
+dev_read_urand(nagios_t)  

 domain_use_interactive_fds(nagios_t)
 # for ps
@@ -97,8 +99,6 @@  

 miscfiles_read_localization(nagios_t)  

-sysnet_read_config(nagios_t)
-

 userdom_dontaudit_use_unpriv_user_fds(nagios_t)  userdom_dontaudit_search_sysadm_home_dirs(nagios_t)  

@@ -108,14 +108,10 @@

 	netutils_domtrans_ping(nagios_t)
 	netutils_signal_ping(nagios_t)
 	netutils_kill_ping(nagios_t)

-
- # cjp: leaked file descriptors:
- #dontaudit ping_t nagios_etc_t:file read;
- #dontaudit ping_t nagios_log_t:fifo_file read;
 ')  

 optional_policy(`
- nis_use_ypbind(nagios_t)

+ auth_use_nsswitch(nagios_t)
 ')  

 optional_policy(`

--

This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message. Received on Wed 30 May 2007 - 13:37:21 EDT

 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service