2008-10-14 20:42:00

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] services_dovecot.patch

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

http://people.fedoraproject.org/~dwalsh/SELinux/F10/services_dovecot.patch

initrc handling

Fix labeling on files only /var/run/dovecot/login/ssl-parameters.dat


Add admin interface

Add policy for deliver
Add domain to connect to dovecot_auth


dovecot uses /tmp

auth reads usr files

auth can communicate with mysql, posfix

Uses nis authentication

Usses gssapi
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iEYEARECAAYFAkj1BBgACgkQrlYvE4MpobPFWgCfU4ww0imrj7QdNMbtmXqrvy/Q
HAQAn3fqbl6uhxc9Z6rZmbrihHk3+Jv3
=kCX2
-----END PGP SIGNATURE-----


2008-10-14 22:59:59

by paul

[permalink] [raw]
Subject: [refpolicy] services_dovecot.patch

On Tue, 14 Oct 2008 16:42:00 -0400
Daniel J Walsh <[email protected]> wrote:

> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> http://people.fedoraproject.org/~dwalsh/SELinux/F10/services_dovecot.patch
>
> initrc handling
>
> Fix labeling on files only /var/run/dovecot/login/ssl-parameters.dat
>
>
> Add admin interface
>
> Add policy for deliver
> Add domain to connect to dovecot_auth
>
>
> dovecot uses /tmp
>
> auth reads usr files
>
> auth can communicate with mysql, posfix
>
> Uses nis authentication
>
> Usses gssapi

Someone was whining on fedora-devel-list today that they'd configured
dovecot to write logs to a directory /var/log/dovecot that they'd
created but were blocked by SELinux. Cue standard anti-SELinux rantlet.
There's currently no dovecot_log_t to enable this easily, so perhaps
that could be added too?

Paul.