2009-03-05 16:01:40

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] admin_usermanage.patch

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

http://people.fedoraproject.org/~dwalsh/SELinux/F11/admin_usermanage.patch


Multiple fixes to passwd and usermanage.

smbd_t sends sigkill to passwd_t

Any confined domain that transitions to another confined domain and can
use run from a user role needs to add the run domain_run command for
other domains, in it's _run function to set up RBAC correctly.

Samba domain controller uses useradd
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkmv92MACgkQrlYvE4MpobM2+ACaAhkDLeQc8Hi3kX/STjDGl7E1
gOEAoOlSjBRJcuSFr5lFmAolzc+ltUnA
=quyS
-----END PGP SIGNATURE-----


2009-03-19 18:21:41

by cpebenito

[permalink] [raw]
Subject: [refpolicy] admin_usermanage.patch

On Thu, 2009-03-05 at 12:01 -0400, Daniel J Walsh wrote:
> http://people.fedoraproject.org/~dwalsh/SELinux/F11/admin_usermanage.patch
>
>
> Multiple fixes to passwd and usermanage.
>
> smbd_t sends sigkill to passwd_t
>
> Any confined domain that transitions to another confined domain and
> can
> use run from a user role needs to add the run domain_run command for
> other domains, in it's _run function to set up RBAC correctly.
>
> Samba domain controller uses useradd

Merged.

--
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150