You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It may be possible to add integration with tools such as sesearch/audit2allow to provide suggestions about how to fix AVC denials. On the other hand, a simpler albeit huge boolean lookup table + common error (e.g. file_t label on files) advice may be of greater benefit.
Given ~10% of the search heads with this app currently installed are known to be running Windows/OS X, and integration with sesearch or similar tools would require an Enterprise Linux / Fedora-based distro, perhaps this feature may not come to pass. Thoughts?
The text was updated successfully, but these errors were encountered:
I don't think you'd need to depend on the availability of sesearch on the search head. There's enough information to implement the basic functionality of setroubleshootd and audit2allow using just the data in the AVC message alone. A lookup table could probably be used to collapse permissions into macros from the SELinux reference policy to generate precise policy rules.
It may be possible to add integration with tools such as sesearch/audit2allow to provide suggestions about how to fix AVC denials. On the other hand, a simpler albeit huge boolean lookup table + common error (e.g. file_t label on files) advice may be of greater benefit.
Given ~10% of the search heads with this app currently installed are known to be running Windows/OS X, and integration with sesearch or similar tools would require an Enterprise Linux / Fedora-based distro, perhaps this feature may not come to pass. Thoughts?
The text was updated successfully, but these errors were encountered: