All of lore.kernel.org
 help / color / mirror / Atom feed
* I am new to selinux
@ 2013-04-11 14:03 Rodney Simioni
  2013-04-11 15:05 ` Daniel J Walsh
  0 siblings, 1 reply; 2+ messages in thread
From: Rodney Simioni @ 2013-04-11 14:03 UTC (permalink / raw)
  To: selinux

[-- Attachment #1: Type: text/plain, Size: 1692 bytes --]

Greetings,

I've been tasked to setup selinux on a web hosting server where users
will have accounts, able to ftp, able to shell, and able to store their
web content.

This server will have some of its services running unconventionally.
This is how I am approaching selinux and please comment if something
concerns you on my way of configuring selinux.

 

I am the developer of this server but I'm also doing system
administration duties. All my code works as expected when the server is
in permissive mode; however, I do see the failed AVC denials in
audit.log.

 

Here are my steps:

 

1.       Run all my tests on the code I have written, which will write
to the audit.log.

2.       Do a audit2why -a, to see the errors and the recommended
solution.

3.       Run all the setsebool commands that was recommended.

4.       Then I'll grep the "Missing type enforcement (TE) allow rule"
AVC errors and pipe them to a file.

5.       I'll create a module from the file and then ' semodule -i'  the
module.

 

Any comments will be greatly appreciated.

 

Rod Simioni

Software Development Engineer II

Verio, Inc.



This email message is intended for the use of the person to whom it has been sent, and may contain information that is confidential or legally protected. If you are not the intended recipient or have received this message in error, you are not authorized to copy, distribute, or otherwise use this message or its attachments. Please notify the sender immediately by return e-mail and permanently delete this message and any attachments. Verio Inc. makes no warranty that this email is error or virus free.  Thank you.

[-- Attachment #2: Type: text/html, Size: 6550 bytes --]

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2013-04-11 15:05 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-04-11 14:03 I am new to selinux Rodney Simioni
2013-04-11 15:05 ` Daniel J Walsh

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.