From mboxrd@z Thu Jan 1 00:00:00 1970 From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Fri, 27 Sep 2013 16:27:40 -0400 Subject: [refpolicy] [PATCH] ssh: Debian sshd is configured to use capabilities In-Reply-To: <1380281767-24268-1-git-send-email-dominick.grift@gmail.com> References: <1380281767-24268-1-git-send-email-dominick.grift@gmail.com> Message-ID: <5245EA3C.5030203@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On Fri 27 Sep 2013 07:36:07 AM EDT, Dominick Grift wrote: > > Signed-off-by: Dominick Grift > diff --git a/policy/modules/services/ssh.te b/policy/modules/services/ssh.te > index 6977e7a..42a0400 100644 > --- a/policy/modules/services/ssh.te > +++ b/policy/modules/services/ssh.te > @@ -245,6 +245,10 @@ > corenet_tcp_bind_xserver_port(sshd_t) > corenet_sendrecv_xserver_server_packets(sshd_t) > > +ifdef(`distro_debian',` > + allow sshd_t self:process { getcap setcap }; > +') > + > tunable_policy(`ssh_sysadm_login',` > # Relabel and access ptys created by sshd > # ioctl is necessary for logout() processing for utmp entry and for w to Merged. -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com