From: Shane Wegner <shane-keyword-selinux.9d5a25@cm.nu>
To: selinux@tycho.nsa.gov
Cc: Russell Coker <russell@coker.com.au>
Subject: Re: Domain Transitions (or the Exim4 policy)
Date: Thu, 18 Dec 2003 23:09:05 -0800 [thread overview]
Message-ID: <20031219070905.GA32075@cm.nu> (raw)
In-Reply-To: <200312191647.45107.russell@coker.com.au>
On Fri, Dec 19, 2003 at 04:47:45PM +1100, Russell Coker wrote:
> Why did you change it to exim4_t? It seems to me that as exim and sendmail
> operate in the same manner it would be better to have a single policy to use
> for them both. This will make it easier to maintain the policy.
Point taken. Exim does seem to use a slightly different
capability set and needs some modified permissions but
they're trivial changes.
> > permissions it needs. Further, when a user sends mail, say
> > echo Hello world |mail
> > exim4 gets spawned but this time in the user_t domain,
> > again without the necessary permissions to write to its
> > spool.
>
> In the sendmail policy it would transition to user_mail_t domain.
After adapting sendmail.te and putting that in per your
suggestion, it does indeed transition to user_mail_t though
I can't figure out how. The problem I'm seeing now though
is from user_mail_t, exim doesn't have permission to wread
its config files. Do I need to give user_mail_t or
user_mail_domain all the privileges given to sendmail_t in
the sendmail policy? Also, is user_mail_t an alias for
some other domain. I'm seeing user_mail_domain in policies
but don't see user_mail_t anywhere save a minor mention
in attrib.te.
Thanks for the suggestions, they were of great help.
Shane
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2003-12-19 7:09 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-12-19 2:45 Domain Transitions (or the Exim4 policy) Shane Wegner
2003-12-19 5:47 ` Russell Coker
2003-12-19 7:09 ` Shane Wegner [this message]
2003-12-19 7:59 ` Russell Coker
2003-12-19 18:03 ` Shane Wegner
2003-12-19 14:59 ` David A. Caplan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20031219070905.GA32075@cm.nu \
--to=shane-keyword-selinux.9d5a25@cm.nu \
--cc=russell@coker.com.au \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.