Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SELinux Advisor #2

Open
doksu opened this issue Mar 25, 2015 · 1 comment
Open

SELinux Advisor #2

doksu opened this issue Mar 25, 2015 · 1 comment

Comments

@doksu
Copy link
Owner

doksu commented Mar 25, 2015

It may be possible to add integration with tools such as sesearch/audit2allow to provide suggestions about how to fix AVC denials. On the other hand, a simpler albeit huge boolean lookup table + common error (e.g. file_t label on files) advice may be of greater benefit.

Given ~10% of the search heads with this app currently installed are known to be running Windows/OS X, and integration with sesearch or similar tools would require an Enterprise Linux / Fedora-based distro, perhaps this feature may not come to pass. Thoughts?

@awillis
Copy link

awillis commented Feb 23, 2021

I don't think you'd need to depend on the availability of sesearch on the search head. There's enough information to implement the basic functionality of setroubleshootd and audit2allow using just the data in the AVC message alone. A lookup table could probably be used to collapse permissions into macros from the SELinux reference policy to generate precise policy rules.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants