From: Luke Kenneth Casson Leighton <lkcl@lkcl.net>
To: Linas Vepstas <linas@austin.ibm.com>
Cc: Stephen Smalley <sds@epoch.ncsc.mil>,
"Fedora SELinux support list for users & developers."
<fedora-selinux-list@redhat.com>,
Colin Walters <walters@verbum.org>,
linux-hotplug-devel@lists.sourceforge.net,
SELinux <SELinux@tycho.nsa.gov>,
Bill Nottingham <notting@redhat.com>,
Nigel Kukard <nkukard@lbsd.net>,
harald@redhat.com
Subject: Re: Lomac questions [was Re: [OT] SELinux vs. other systems]
Date: Thu, 02 Sep 2004 20:05:40 +0000 [thread overview]
Message-ID: <20040902200540.GL5745@lkcl.net> (raw)
In-Reply-To: <20040902172907.GB9645@austin.ibm.com>
On Thu, Sep 02, 2004 at 12:29:07PM -0500, Linas Vepstas wrote:
> Is the 'broken-ness' the fact that grandma failed to run an anti-virus
> scanner and verify checksums, yada yada, before elevating the
> priveldge on the downloaded software?
[this is all with the strict policy 1.14 mostly sortof btw]
i've installed clamav, spamassassin, razor and pyzor.
oh, and freshclam.
i then found a little script called clamassassin [google], i then
searched [google] for some advice on how to set up kmail filters.
kmail, the clamassassin script and spamc all run under the user
context.
the user context is given the right to bind to servers.
spamd and clamd both run as servers: they have their own
policies that restrict their operation to what is known
that they presently do, but they are allowed to listen to
incoming requests [from spamc and the clamassassin script
respectively.]
selinux doesn't in the _slightest_ bit get in the way.
the only thing that i did find is that razor is a complete pain.
it endeavours to write log files into /root/razor.log, /tmp/razor.log,
/razor.log, it's a pain, and selinux is _exactly_ the sort of thing
that can detect - and stop! - this behaviour.
pyzor appears to be a lot less haphazard.
also nobody else appears to have tried to run freshclam [automatic
update script] before now, so i had to hack the clamav.te policy
a bit to get it to run.
l.
-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_idP47&alloc_id\x10808&op=click
_______________________________________________
Linux-hotplug-devel mailing list http://linux-hotplug.sourceforge.net
Linux-hotplug-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/linux-hotplug-devel
prev parent reply other threads:[~2004-09-02 20:05 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-08-30 17:37 [idea] udev + selinux Nigel Kukard
2004-08-30 20:31 ` Luke Kenneth Casson Leighton
2004-08-31 5:02 ` Nigel Kukard
2004-08-31 9:49 ` Luke Kenneth Casson Leighton
2004-08-31 10:27 ` Nigel Kukard
2004-08-31 12:46 ` Luke Kenneth Casson Leighton
2004-08-31 11:26 ` Luke Kenneth Casson Leighton
2004-08-31 16:07 ` Luke Kenneth Casson Leighton
2004-08-31 16:46 ` Nigel Kukard
2004-08-31 19:18 ` Luke Kenneth Casson Leighton
2004-08-31 19:26 ` Stephen Smalley
2004-08-31 20:02 ` Luke Kenneth Casson Leighton
2004-08-31 21:18 ` Jim McCullough
2004-08-31 23:26 ` Luke Kenneth Casson Leighton
2004-08-31 22:44 ` [OT] SELinux vs. other systems [was Re: [idea] udev + selinux] Linas Vepstas
2004-09-01 14:23 ` Richard Troth
2004-09-01 17:25 ` Linas Vepstas
2004-09-02 16:10 ` Stephen Smalley
2004-09-02 17:29 ` Lomac questions [was Re: [OT] SELinux vs. other systems] Linas Vepstas
2004-09-02 20:05 ` Luke Kenneth Casson Leighton [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20040902200540.GL5745@lkcl.net \
--to=lkcl@lkcl.net \
--cc=SELinux@tycho.nsa.gov \
--cc=fedora-selinux-list@redhat.com \
--cc=harald@redhat.com \
--cc=linas@austin.ibm.com \
--cc=linux-hotplug-devel@lists.sourceforge.net \
--cc=nkukard@lbsd.net \
--cc=notting@redhat.com \
--cc=sds@epoch.ncsc.mil \
--cc=walters@verbum.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).