2010-02-23 21:42:30

by Daniel Walsh

[permalink] [raw]
Subject: [refpolicy] services_asterisk.patch

http://people.fedoraproject.org/~dwalsh/SELinux/F13/services_asterisk.patch


+ asterisk_manage_lib_files(logrotate_t)
+ asterisk_exec(logrotate_t)

Needs net_admin

Drops capabilities
connects to unix_stream

execs itself

Requests kernel load modules

Execs shells


Connects to postgresql and snmp ports

Reads urand and generic usb devices


Has mysql and postgresql back ends
sends mail