2010-06-02 20:28:17

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] roles_auditadm.patch

http://people.fedoraproject.org/~dwalsh/SELinux/F14/roles_auditadm.patch

Auditadmin should be able to connect to the syslog. Dontaudit search /root.


2010-07-06 12:27:28

by cpebenito

[permalink] [raw]
Subject: [refpolicy] roles_auditadm.patch

On 06/02/10 16:28, Daniel J Walsh wrote:
> http://people.fedoraproject.org/~dwalsh/SELinux/F14/roles_auditadm.patch
>
> Auditadmin should be able to connect to the syslog. Dontaudit search /root.

Not clear why auditadm would connecting to syslog; what program are they
running? Also, the interface doesn't exist.

--
Chris PeBenito
Tresys Technology, LLC
http://www.tresys.com | oss.tresys.com

2010-07-12 14:59:37

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] roles_auditadm.patch

On 07/06/2010 08:27 AM, Christopher J. PeBenito wrote:
> On 06/02/10 16:28, Daniel J Walsh wrote:
>> http://people.fedoraproject.org/~dwalsh/SELinux/F14/roles_auditadm.patch
>>
>> Auditadmin should be able to connect to the syslog. Dontaudit search
>> /root.
>
> Not clear why auditadm would connecting to syslog; what program are they
> running? Also, the interface doesn't exist.
>

This is some old stuff, but I guess it would have to do with changing
the way syslog worked.

Probably needs the ability to manage the syslog/auditd process also.

2010-07-12 16:24:57

by domg472

[permalink] [raw]
Subject: [refpolicy] roles_auditadm.patch

On 07/12/2010 04:59 PM, Daniel J Walsh wrote:
> On 07/06/2010 08:27 AM, Christopher J. PeBenito wrote:
>> On 06/02/10 16:28, Daniel J Walsh wrote:
>>> http://people.fedoraproject.org/~dwalsh/SELinux/F14/roles_auditadm.patch
>>>
>>> Auditadmin should be able to connect to the syslog. Dontaudit search
>>> /root.
>>
>> Not clear why auditadm would connecting to syslog; what program are they
>> running? Also, the interface doesn't exist.
>>
>
> This is some old stuff, but I guess it would have to do with changing
> the way syslog worked.
>
> Probably needs the ability to manage the syslog/auditd process also.

Any particular reason why these "mls roles" need to be login users and
unlike webadm etc:?

userdom_unpriv_user_template(auditadm)

userdom_base_user_template(webadm)




> _______________________________________________
> refpolicy mailing list
> refpolicy at oss.tresys.com
> http://oss.tresys.com/mailman/listinfo/refpolicy


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 261 bytes
Desc: OpenPGP digital signature
Url : http://oss.tresys.com/pipermail/refpolicy/attachments/20100712/a5462d40/attachment-0001.bin

2010-07-12 17:35:53

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] roles_auditadm.patch

On 07/12/2010 12:24 PM, Dominick Grift wrote:
> On 07/12/2010 04:59 PM, Daniel J Walsh wrote:
>> On 07/06/2010 08:27 AM, Christopher J. PeBenito wrote:
>>> On 06/02/10 16:28, Daniel J Walsh wrote:
>>>> http://people.fedoraproject.org/~dwalsh/SELinux/F14/roles_auditadm.patch
>>>>
>>>> Auditadmin should be able to connect to the syslog. Dontaudit search
>>>> /root.
>>>
>>> Not clear why auditadm would connecting to syslog; what program are they
>>> running? Also, the interface doesn't exist.
>>>
>>
>> This is some old stuff, but I guess it would have to do with changing
>> the way syslog worked.
>>
>> Probably needs the ability to manage the syslog/auditd process also.
>
> Any particular reason why these "mls roles" need to be login users and
> unlike webadm etc:?
>
> userdom_unpriv_user_template(auditadm)
>
> userdom_base_user_template(webadm)
>
>
I am not sure, In MLS mode in RHEL5 we allowed you to login directly as
auditadm_t on MLS boxes. But I would prefer to move to

userdom_base_user_template(auditadm)
>
>
>> _______________________________________________
>> refpolicy mailing list
>> refpolicy at oss.tresys.com
>> http://oss.tresys.com/mailman/listinfo/refpolicy
>
>
>
>
> _______________________________________________
> refpolicy mailing list
> refpolicy at oss.tresys.com
> http://oss.tresys.com/mailman/listinfo/refpolicy