All of lore.kernel.org
 help / color / mirror / Atom feed
* fwknop, fwknopd,  fwknop_serv
@ 2011-04-01 16:10 Bill Chimiak
  2011-04-01 16:35 ` Dominick Grift
  0 siblings, 1 reply; 3+ messages in thread
From: Bill Chimiak @ 2011-04-01 16:10 UTC (permalink / raw)
  To: selinux-mailing-list

fwknop is a single passphrase authorization system.
Fairly cool.  selinux did not like fwknop out of the box.
It wanted a new module:

module iptab2log 1.0;

require {
        type var_log_t;
        type iptables_t;
        class file write;
}

#============= iptables_t ==============
allow iptables_t var_log_t:file write;

It works now.  Was there another way to do this?
William J. Chimiak
Laboratory for Telecommunication Sciences 
8080 Greenmead Drive,  College Park, MD 20740
301-422-5217

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2011-04-01 17:09 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-04-01 16:10 fwknop, fwknopd, fwknop_serv Bill Chimiak
2011-04-01 16:35 ` Dominick Grift
2011-04-01 17:09   ` Daniel J Walsh

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.