From: Simon Peter Nicholls <simon@mintsource.org>
To: Dominick Grift <domg472@gmail.com>
Cc: selinux@tycho.nsa.gov
Subject: Re: Trouble logging in through SSH
Date: Sun, 06 Feb 2011 10:28:48 +0100 [thread overview]
Message-ID: <4D4E69D0.50808@mintsource.org> (raw)
In-Reply-To: <4D4D5038.2090403@gmail.com>
On 05/02/11 14:27, Dominick Grift wrote:
> By the way, these policy related questions should go to
> refpolicy@oss.tresys.com maillist.
Hi Dominick, thanks for your replies to my issues.
When I hit trouble, I thought I had hit something other than regular
policy issues, but this was incorrect. I have missing access_vectors,
and face some other issues (due to a combination of recent software and
non-standard file locations), but all appear to be surmountable through
a custom policy build.
I've learned a lot in a short time, thanks in large part to reading some
key posts in this mailing list, and my system is firmly in the realm of
policy tweaking now. Mostly I'm twiddling booleans and changing file
contexts to match Arch Linux at this point, with cron and syslog-ng the
only services with issues. My "semanage permissive -a" functionality is
broken, as the "/var/lib/selinux" path I see hardcoded into semanage
does not exist on my system, but it was no bother to hand code a
permissive module to get my logging working for now. So I can run
enforcing from boot whilst I finish up, no problem.
It looks like Fedora have already addressed some of the core refpolicy
issues I've faced (problems unrelated to Arch file locations), but
patches had not made it upstream the last time I checked. I'd also like
to see a passenger module make it into refpolicy. So, I still have some
outstanding refpolicy queries, which I'll take over to the mailing list
you mention.
Thanks again.
--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next prev parent reply other threads:[~2011-02-06 9:28 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-02-04 23:22 Trouble logging in through SSH Simon Peter Nicholls
2011-02-05 8:33 ` Simon Peter Nicholls
2011-02-05 13:26 ` Dominick Grift
2011-02-05 13:27 ` Dominick Grift
2011-02-06 9:28 ` Simon Peter Nicholls [this message]
2011-02-06 10:52 ` Dominick Grift
2011-02-05 13:37 ` Dominick Grift
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4D4E69D0.50808@mintsource.org \
--to=simon@mintsource.org \
--cc=domg472@gmail.com \
--cc=selinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.