All of lore.kernel.org
 help / color / mirror / Atom feed
From: Debian User <rogelio@evoworks.evoserve.com>
To: Russell Coker <russell@coker.com.au>
Cc: SE Linux <selinux@tycho.nsa.gov>
Subject: Re: new Debian package
Date: Mon, 27 May 2002 11:53:41 +0800	[thread overview]
Message-ID: <3CF1ADC5.1070600@evoworks.evoserve.com> (raw)
In-Reply-To: 20020526071153.488F71C0F@lyta.coker.com.au

Russell Coker wrote:

>On Sun, 26 May 2002 08:45, Russell Coker wrote:
>
>>On Sun, 26 May 2002 03:36, Debian User wrote:
>>
>>>>I've just uploaded a new Debian package, this one has the latest patches
>>>>and new policy that works a lot better.  I now have a Debian machine
>>>>running in enforcing mode with a policy that is not much different from
>>>>the default in my package.  It's running as an ADSL gateway machine
>>>>(pppoatm with SpeedTouch USB driver), a web server, and has the courier
>>>>POP server running.
>>>>
>>>>As the basic stuff is working it won't be too difficult for you to add
>>>>support for other daemons etc.
>>>>
>>>I tried it just now policy compilation fails with:
>>>
>>>/usr/sbin/checkpolicy -o policy.9 policy.conerror in the statement
>>>ending on line 13924 (token ';'): unknown type ipsec_file_t
>>>
>>>/usr/sbin/checkpolicy: error(s) encountered while parsing configuration
>>>
>>This means that some file you are using has a rule involving the
>>ipsec_file_t while you have not included the ipsec.te file.  Including
>>ipsec.te is one way of solving the problem, but a better solution (if you
>>don't want ipsec) is to find the file in question and fix it.
>>
>
>As a follow up to this, that turned out to be a bug in my sample policy.  
>Just remove the lines in question from initrc.te.
>
Well i got my old and new policy files mixed up and there was a bug. I 
do need ipsec.



--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2002-05-27  3:53 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-05-25 19:56 new Debian package Russell Coker
2002-05-26  1:36 ` Debian User
2002-05-26  6:45   ` Russell Coker
2002-05-26  7:11   ` Russell Coker
2002-05-27  3:53     ` Debian User [this message]
     [not found] <Pine.GSO.4.33.0204250829440.4789-100000@raven>
2002-04-25 13:43 ` Russell Coker
2002-04-25 14:00   ` Stephen Smalley
2002-04-25 14:46     ` Russell Coker
  -- strict thread matches above, loose matches on Subject: below --
2002-04-24 23:40 Russell Coker

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=3CF1ADC5.1070600@evoworks.evoserve.com \
    --to=rogelio@evoworks.evoserve.com \
    --cc=russell@coker.com.au \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.