From: Dale Amon <amon@vnl.com>
To: selinux <selinux@tycho.nsa.gov>
Subject: Re: Still no authentication from new debian packages
Date: Tue, 25 Nov 2003 23:11:00 +0000 [thread overview]
Message-ID: <20031125231100.GQ2718@vnl.com> (raw)
In-Reply-To: <20031125205010.GA2174@rom.cip.informatik.uni-muenchen.de>
On Tue, Nov 25, 2003 at 09:50:11PM +0100, Thomas Bleher wrote:
> I'm using Russel's packages on a new Debian install and am booting up
> fine in enforcing mode. The one thing I had to change in policy to be
> able to login was to add the line
>
> allow system_chkpwd_t tty_device_t:chr_file rw_file_perms;
>
> to macros/program/chkpwd_macros.te
>
> I also appended the line
> session required pam_selinux.so
> to /etc/pam.d/{login,ssh}
That is worth a look also. But I think Russell might
need to look into some of this... the object of what
I'm doing is not to get selinux working on this
machine per-se. It's to verify that I can define a
full build process from bare disk to running selinux
with as little fiddling as possible.
I suspect I'll be annoying Russ with trivia for
quite some time.
--
------------------------------------------------------
Dale Amon amon@islandone.org +44-7802-188325
International linux systems consultancy
Hardware & software system design, security
and networking, systems programming and Admin
"Have Laptop, Will Travel"
------------------------------------------------------
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2003-11-25 23:11 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-11-25 14:02 Still no authentication from new debian packages Dale Amon
2003-11-25 18:19 ` Dale Amon
[not found] ` <20031125205010.GA2174@rom.cip.informatik.uni-muenchen.de>
2003-11-25 23:00 ` Dale Amon
2003-11-25 23:11 ` Dale Amon [this message]
2003-11-26 3:54 ` Russell Coker
2003-11-26 10:14 ` Dale Amon
2003-11-30 19:10 ` Manoj Srivastava
2003-11-30 21:40 ` Dale Amon
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20031125231100.GQ2718@vnl.com \
--to=amon@vnl.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.