All of lore.kernel.org
 help / color / mirror / Atom feed
From: Simon Peter Nicholls <simon@mintsource.org>
To: Dominick Grift <domg472@gmail.com>
Cc: selinux@tycho.nsa.gov
Subject: Re: Trouble logging in through SSH
Date: Sun, 06 Feb 2011 10:28:48 +0100	[thread overview]
Message-ID: <4D4E69D0.50808@mintsource.org> (raw)
In-Reply-To: <4D4D5038.2090403@gmail.com>

On 05/02/11 14:27, Dominick Grift wrote:
> By the way, these policy related questions should go to
> refpolicy@oss.tresys.com maillist.

Hi Dominick, thanks for your replies to my issues.

When I hit trouble, I thought I had hit something other than regular 
policy issues, but this was incorrect. I have missing access_vectors, 
and face some other issues (due to a combination of recent software and 
non-standard file locations), but all appear to be surmountable through 
a custom policy build.

I've learned a lot in a short time, thanks in large part to reading some 
key posts in this mailing list, and my system is firmly in the realm of 
policy tweaking now. Mostly I'm twiddling booleans and changing file 
contexts to match Arch Linux at this point, with cron and syslog-ng the 
only services with issues. My "semanage permissive -a" functionality is 
broken, as the "/var/lib/selinux" path I see hardcoded into semanage 
does not exist on my system, but it was no bother to hand code a 
permissive module to get my logging working for now. So I can run 
enforcing from boot whilst I finish up, no problem.

It looks like Fedora have already addressed some of the core refpolicy 
issues I've faced (problems unrelated to Arch file locations), but 
patches had not made it upstream the last time I checked. I'd also like 
to see a passenger module make it into refpolicy. So, I still have some 
outstanding refpolicy queries, which I'll take over to the mailing list 
you mention.

Thanks again.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2011-02-06  9:28 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-02-04 23:22 Trouble logging in through SSH Simon Peter Nicholls
2011-02-05  8:33 ` Simon Peter Nicholls
2011-02-05 13:26   ` Dominick Grift
2011-02-05 13:27   ` Dominick Grift
2011-02-06  9:28     ` Simon Peter Nicholls [this message]
2011-02-06 10:52       ` Dominick Grift
2011-02-05 13:37 ` Dominick Grift

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4D4E69D0.50808@mintsource.org \
    --to=simon@mintsource.org \
    --cc=domg472@gmail.com \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.