All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] Using nagios with SELinux on Debian
@ 2014-05-21 11:30 Gereon Kremer
  2014-05-21 13:32 ` Mika Pflüger
  2014-06-10  4:05 ` Russell Coker
  0 siblings, 2 replies; 3+ messages in thread
From: Gereon Kremer @ 2014-05-21 11:30 UTC (permalink / raw)
  To: refpolicy

Hi all,

I'm trying to use nagios on a debian with SELinux.
Although there is a nagios policy, there are various avc denials, mostly
plugins that are denied to access /var/lib/nagios3/spool/

I looked through the nagios policy and it seems that some things are
just incomplete:
There are several classes of plugins (admin, checkdisk, mail. services,
system, unconfined) but they all try to access the same spool folder and
there are no rules to allow this access: Neither rules that allow all
plugins to access a specific file class, nor a rule that labels the
spool folder. (there is a rule for /var/spool/nagios3/, but this folder
does not exist on my machine...)
Also, the webserver (apache in my case) tries to access cache files
which is not allows by the nagios policy...

What is the status of this policy? Should it actually work? Or is it
just broken for debian?

-- 
Gereon Kremer
Lehr- und Forschungsgebiet Theorie Hybrider Systeme
RWTH Aachen
Tel: +49 241 80 21243

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2014-06-10  4:05 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2014-05-21 11:30 [refpolicy] Using nagios with SELinux on Debian Gereon Kremer
2014-05-21 13:32 ` Mika Pflüger
2014-06-10  4:05 ` Russell Coker

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.