Research Menu

.
Skip Search Box

SELinux Mailing List

iptables reads etc runtime files, execed out of failto ban with terminal redirected

From: dwalsh_at_redhat.com
Date: Wed, 30 May 2007 10:17:26 -0400

  • nsaserefpolicy/policy/modules/system/iptables.te 2007-05-29 14:10:58.000000000 -0400
    +++ serefpolicy-3.0.1/policy/modules/system/iptables.te 2007-05-30 09:22:02.000000000 -0400
    @@ -56,6 +56,7 @@ domain_use_interactive_fds(iptables_t)

 files_read_etc_files(iptables_t)
+files_read_etc_runtime_files(iptables_t)
 

 init_use_fds(iptables_t)
 init_use_script_ptys(iptables_t)
@@ -77,6 +78,10 @@
 userdom_use_all_users_fds(iptables_t)  

 optional_policy(`
+ fail2ban_append_log(iptables_t)
+')
+
+optional_policy(`

 	firstboot_use_fds(iptables_t)
 	firstboot_rw_pipes(iptables_t)

 ')
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Wed 30 May 2007 - 13:37:31 EDT
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service