All of lore.kernel.org
 help / color / mirror / Atom feed
* Problem Setting Policy To Enforcing Mode
@ 2008-11-21 14:59 Rahul Jain
  2008-11-21 15:45 ` Justin P. Mattock
                   ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: Rahul Jain @ 2008-11-21 14:59 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 692 bytes --]

Hi All,
 
This is the first time I am writing to this mailing list in hope of receiving help. I am trying to port reference policy by tresys on Montavista. I am able to run the policy well in permmisive mode with no avc messages in audit log, kern.log or messages. But when I put the policy into enforcing mode my system fails to boot, reason seems to be problem with init process. I am not able to debug the problem because no avc messages are generated for the same, probably because the issue comes up even before logging deamons start. Is there anyway I can debug my policy and log the avc messages from the very beginning of the system startup.
 
Rahul Jain
Rahul Jain  


      

[-- Attachment #2: Type: text/html, Size: 938 bytes --]

^ permalink raw reply	[flat|nested] 9+ messages in thread
* Problem Setting Policy To Enforcing Mode
@ 2008-11-22 11:09 Rahul Jain
  2008-11-22 17:18 ` Justin P. Mattock
  2008-11-24 13:47 ` Stephen Smalley
  0 siblings, 2 replies; 9+ messages in thread
From: Rahul Jain @ 2008-11-22 11:09 UTC (permalink / raw)
  To: selinux; +Cc: justinmattock, sds, dwalsh

[-- Attachment #1: Type: text/plain, Size: 951 bytes --]

Thankyou all for your kind help.
 
Finally I was able to boot my policy. As suggested, I removed dontaudit rules from my policy by doing "make enableaudit". Then I did some quick fixes and was finally able to boot the policy. However I am still facing some issues:
Firstly - My syslog daemon takes too long to start almost 10 min. Please note my test systems are high end multiprocessor express servers with 8 GB of RAM.
Secondly: I am not able to come back to permissive mode, not even by login as sysadm_r role. My file system is read only and so I am not able to edit the /etc/selinux/config file. "setenforce" command temperoraly puts the policy in permissive mode but still config file could not be edited. I even tried it in linux single user mode, but the problem persists. Is it the property of the tresys reference policy or my policy is still not behaving properly?
I reallly appreciate your kind help
 
Thanks 
Rahul    


      

[-- Attachment #2: Type: text/html, Size: 1232 bytes --]

^ permalink raw reply	[flat|nested] 9+ messages in thread
* Problem Setting Policy To Enforcing Mode
@ 2008-11-24 17:37 Rahul Jain
  2008-11-24 18:23 ` Justin P. Mattock
  0 siblings, 1 reply; 9+ messages in thread
From: Rahul Jain @ 2008-11-24 17:37 UTC (permalink / raw)
  To: sds, justinmattock, dwalsh; +Cc: selinux

[-- Attachment #1: Type: text/plain, Size: 693 bytes --]

Hi All,
 
Thanks you all, for your kind support. After your suggestion I was able to fix all my problems. So to put my policy in enforcing mode I deleted the "dontaudit" rule using "make enableaudit' . Then I did the fixes. My syslogd was taking long time to start because there were still some avc messages left, I fixed them and issue got resolved.  I was able to come back to permissive by adjusting the DAC permissions of the /etc/selinux/config file. My initial context on login was root:sysadm_r:sysadm_t. I checked the "sestatus" to see that my policy got loaded and that it is enforcing mode.
 
So finally my policy is up and running. 
 
Thanks and Regards
Rahul 
 


      

[-- Attachment #2: Type: text/html, Size: 953 bytes --]

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2008-11-24 18:23 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2008-11-21 14:59 Problem Setting Policy To Enforcing Mode Rahul Jain
2008-11-21 15:45 ` Justin P. Mattock
2008-11-21 18:37 ` Stephen Smalley
2008-11-21 19:41 ` Daniel J Walsh
  -- strict thread matches above, loose matches on Subject: below --
2008-11-22 11:09 Rahul Jain
2008-11-22 17:18 ` Justin P. Mattock
2008-11-24 13:47 ` Stephen Smalley
2008-11-24 17:37 Rahul Jain
2008-11-24 18:23 ` Justin P. Mattock

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.