All of lore.kernel.org
 help / color / mirror / Atom feed
* FC5 policy
@ 2006-09-23 14:34 Russell Coker
  2006-09-23 14:54 ` Joshua Brindle
  0 siblings, 1 reply; 8+ messages in thread
From: Russell Coker @ 2006-09-23 14:34 UTC (permalink / raw)
  To: SE-Linux, Daniel Walsh

http://www.coker.com.au/selinux/fc5/

At the above URL I have my latest packages of FC5 policy with patch and 
source.  They compile the policy with amavis and clamav policy in base (which 
can't be included in an FC5 update as the tools are broken and don't support 
policy moving from a module to base), they have Postgrey policy compiled in, 
and they have a few other policy changes (such as allowing unconfined_t to 
kill unlabeled_t processes).

Also my patch removes some unnecessary and inappropriate access from some 
domains.  I know that most people don't like removing access from processes, 
but I think we need to use the principle of least-privilege more seriously.

-- 
russell@coker.com.au
http://etbe.blogspot.com/          My Blog

http://www.coker.com.au/sponsorship.html Sponsoring Free Software development

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 8+ messages in thread
* FC5 policy
@ 2006-07-16  3:32 Russell Coker
  0 siblings, 0 replies; 8+ messages in thread
From: Russell Coker @ 2006-07-16  3:32 UTC (permalink / raw)
  To: SE-Linux

http://www.coker.com.au/selinux/fc5/

At the above URL I have a policy patch for FC5 against the latest Fedora 
package (2.2.47-3.fc5) and some RPMs of it.  The changelog is below:

- Makes Amavis, Clamav, and Postgrey work, and work with Postfix.
- Makes the Apache policy build with the latest policycoreutils.
- Started to fix the mailman issues, it still needs more work and some package
  bug fixes to get it going properly.
- Allowed Samba to talk to CUPS.
- Allowed semanage to talk to the controlling terminal.
- Allowed unconfined domains to see unlabeled_t processes and kill them.

-- 
http://www.coker.com.au/selinux/   My NSA Security Enhanced Linux packages
http://www.coker.com.au/bonnie++/  Bonnie++ hard drive benchmark
http://www.coker.com.au/postal/    Postal SMTP/POP benchmark
http://www.coker.com.au/~russell/  My home page

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2006-09-25 17:56 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-09-23 14:34 FC5 policy Russell Coker
2006-09-23 14:54 ` Joshua Brindle
2006-09-23 22:13   ` Russell Coker
2006-09-23 23:58     ` Joshua Brindle
2006-09-24  0:31       ` Russell Coker
2006-09-24  1:02         ` Joshua Brindle
2006-09-25 17:57         ` Christopher J. PeBenito
  -- strict thread matches above, loose matches on Subject: below --
2006-07-16  3:32 Russell Coker

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.