View Full Version : Fedora SELinux Support
- SLIDE download
- Running sshd inside mock
- New benchmark on SELINUX and Fedora 15 from Phoronix
- File Labeling
- Confined Users & SELinux Denials
- SELinux "upgrade" issues
- Is it possible to run chromium in a SELinux sandbox?
- clamd -selinux Should I allow?
- clamd -selinux Should I allow?
- How can firefox (sometimes) make memory executable?
- How can firefox (sometimes) make memory executable?
- TS under SELinux policy
- Please sync with upstream of sepgsql_contexts
- SEL & Spamassassin
- SELinux repository for Red Hat
- multipath: allow mapper/mpath specfifications in kickstart.
- add textrel_shlib_t in package %post or in selinux-policy?
- fedora 14 packagekitd avc messages
- sandbox: Thunderbird + Enigmail/GPG
- I wrote up an semanage bash command completion script.
- (not sandboxed) firefox AVCs (execstack)
- mouse pointer stuck in browser sandbox window
- sandbox & Fonts (Cosmetic Issue)
- Firefox & Sandbox - F14
- problem with likewise and audit messages
- problem with likewise and audit messages
- interesting group of AVCs
- Cannot disable SELinux
- Require your partnership & co-operation for Investment
- specifying the destination of '-i' files/dirs
- nagios plugins with state files
- Upgrade F13 -> F14: gdm-session-wor / login denials
- excluding auditd events
- SELinux is preventing /usr/bin/skype from mmap_zero access on the memprotect Unknown.
- SELinux is preventing /usr/bin/skype from mmap_zero access on the memprotect Unknown.
- non permanent '-H'
- Fedora 14 does not respect /etc/sysconfig/selinux?
- Fedora 14 does not respect /etc/sysconfig/selinux?
- During startup, many failed to set security context msgs
- F13" SeLinux Troubleshooter no longer starts
- new policy modules submission
- new policy modules submission
- modifying the Xephyr window title (patch)
- Pointer to known threats to test sVirt/SELinux for LXC/KVM
- dontaudit statement specifics
- iptables match based on source security context?
- MLS and Desktop ENvironment
- 3
- MLS and back from runlevel 3
- CVE-2011-0997: How strictly confined is dhcpc_t?
- CVE-2011-0997: How strictly confined is dhcpc_t?
- about restarting services and user domains F14
- Linux Security Summit 2011 - Announcement and CFP
- policy issue with munin
- unconfined domains and Dan Walsh's article
- mkctype is no longer useful.
- serefpolicy: named getattr AVC accessing /dev/random
- i get this on rawhide.
- sandbox: changed handling of /tmp (2.0.83-33.7.fc13.x86_64)
- 3 what looks like bugs in rawhide policy
- eggdrop policy module
- logrotate accessing /root avc messages
- Set SELinux context of host ssh keys correctly after reinstallation
- update breaks sandbox (2.0.83-33.3.fc13.x86_64)
- update breaks sandbox (2.0.83-33.3.fc13.x86_64)
- Restrict httpd network connections to a specific network interface?
- nginx policy
- Restrict httpd network connections to a specific network interface?
- Restrict httpd network connections to a specific network interface?
- Restrict httpd network connections to a specific network interface?
- help adding a type attribute to a domain
- denying despite allow rule
- Sorry about cross posting to multiple lists.
- reference policy
- AW: selinux Digest, Vol 84, Issue 10
- Change xhost auth when doing a liveinst (#663294)
- Restrict unconfined_u access to a dir in targed mode
- need to superseed default file context for virtualbox files but no method works
- need to superseed default file context for virtualbox files but no method works
- semodule -b base.pp -- Segmentation fault.
- recently-used.xbel wrong context
- recently-used.xbel wrong context
- Rawhide AVC denials
- systemd to require selinux-policy?
- error :: chrome's global requirements were not met
- chrome access of high energy physics library
- Need help restricting root access to a file or directory.
- New file getting different context than what restorecond specifies
- AVC report from command line
- HOWTO Logging tcp binding on permissive mode
- Right context for /var/spool/cron/crontabs/root
- mod_passenger and Rails 3 module work
- smartd and 3ware
- smartd and 3ware
- Using dyntransition to reduce privileges for Web application
- mysql_upgrade selinux issues
- nscd AVC
- F14 - NVIDIA & Labels
- Matlab
- Matlab
- udev and secure_mode_insmod in selinux-policy-3.9.7-10.fc14 and later
- Another "execstack" (AviDemux)
- udev and secure_mode_insmod in selinux-policy-3.9.7-10.fc14 and later
- GIMP help shouldn't need execstack, should it?
- SELinux denies qmailadmin access
- SELinux and Shorewall with IPSets (FC14)
- Trouble sending mail from PHP scripts
- Using audti2why with tail?
- Denied for com='ps' name='stat' {open} {read} {search}
- Attention: Beneficiary
- Denied for com='ps' name='stat' {open} {read} {search}
- razor policy
- sshd_t & guest_t - Boolean suggestion
- Type aliases & sesearch
- Getting a RuntimeError: Invalid argument from _seinfo
- Reporting denials which already exist in bugzilla
- F13: nautilus & mmap
- F13: nautilus & mmap
- Nero for Linux & rpm initial labels
- Nero for Linux & rpm initial labels
- No AVC when sshd is mislabeled
- No AVC when sshd is mislabeled
- selinux policy for encrypted files
- The concept of unconfined_t
- avc: smartcard token login
- Issues logging into to more than one system
- avc: smartcard token login
- touch & how labels are created
- touch & how labels are created
- Fwd: http AVC
- http AVC
- proftpd AVC on Rawhide
- AVC bluetoothd
- Alexander Slesarev wants to stay in touch on LinkedIn
- Fedora 14 AVCs
- system shuts down during file system relabel
- building go compiler
- socket files and ruby/passenger
- Please review: Make a confined kernel boot.
- Fix typo in interface name
- Selinux and pyzor issues Fedora 14
- iptables AVC
- What is missing with this policy
- Named and /dev/random Fedora 14
- Named and /dev/random Fedora 14
- node-specific rules
- sandbox in X11 root window on RHEL6
- 26 alerts as of updating to rawhide now that Fedora 14 is out :(
- sealerts upon updating to rawhide from F14
- httpd_sys_content_t
- selinux blocking access, no AVC warnings in /var/log/messages or /var/log/audit/audit.log
- selinux blocking access, no AVC warnings in /var/log/messages or /var/log/audit/audit.log
- tzdata AVC
- selinux policy UBAC question
- Come spy on me Facebook Port
- Seek for help
- Transitions for files.
- paths
- Addition of selinux users causes "Multiple same specifications" warnings during startup
- why label /dev/hugepages directory hugetlbfs_t?
- cgi over nfs
- httpd_use_nfs
- F11 VSFTPD post install problem
- F13: SELinux is preventing /usr/bin/updatedb "read" access on My Documents
- F13: SELinux is preventing /usr/bin/updatedb "read" access on My Documents
- F13: SELinux is preventing /usr/sbin/smbd "quotaget" access
- odd message - execmod related
- Is setroubleshoot-server designed for a server?
- error: ssh_selinux_getctxbyname: Failed to get default SELinux security context
- error: ssh_selinux_getctxbyname: Failed to get default SELinux security context
- Selinux Audit -- Rawhide (F15) Deprecated entry?
- SELinux and Rsyslog
- F13: Unable to mount ntfs-3g, option: 'context=' no longer supported?
- F13: Unable to mount ntfs-3g, option: 'context=' no longer supported?
- F13: Unable to mount ntfs-3g, option: 'context=' no longer supported?
- Statement precedence/priority (neverallow)
- genfscon question
- secmark=XXX mapping
- Labeling of ~/.local, ~/.config, ... owned by gnome though not gnome specific
- Labeling of ~/.local, ~/.config, ... owned by gnome though not gnome specific
- What's the command...?
- Fedora UBAC feature
- Fedora UBAC feature
- SELinux user domain policy question
- sandbox: open new firefox tab from outside
- openvpn and script execution
- openvpn and script execution
- openvpn and script execution
- Giving httpd access to a mounted NTFS volume
- audit log not being rotated
- wine preloader? being denied by selinux
- wine preloader? being denied by selinux
- sandbox: close one window -> closes them all
- setroubleshootd dead but pid file exists
- setroubleshootd dead but pid file exists
- pipefs AVC
- netif labelling
- Issue with Gnome setting?
- .autorelabel on mounted filesystems
- NFSD warning?
- NFSD warning?
- Clamd - again...
- using port (sub)ranges
- Create denial on nshadow when logging in with an expired password
- sandbox cleanup?
- uid 0 <- Xorg <- Xephyr <- $program <- $exploit
- uid 0 <- Xorg <- Xephyr <- $program <- $exploit
- This isn't nice
- Add dlabel confirmation dialog to interactive installs (#570053)
- Support for Brocade FCoE/CEE to PCIe CNAs (#549677)
- Add xts module to initrd (#553411)
- Add support for LSI 3ware 97xx SAS/SATA RAID Controller (#572341)
- Support macro documantation
- F12/3: SELinux is preventing /usr/bin/perl from binding to port XXXXX
- F12/3: SELinux is preventing /usr/bin/perl from binding to port XXXXX
- SELinux integration in LDAP
- SELinux integration in LDAP
- Sample Passenger/Rails policy for review
- sandbox: firefox
- avc { module_request, relabelfrom }: openvpn->tun
- avc { module_request, relabelfrom }: openvpn->tun
- Mlogc problem after aupgrade to F13
- Mlogc problem after aupgrade to F13
- A sendmail problem
- SELINUX_ERR about sendmail (postfix version) on F-13
- dac_override and dac_read_search ... again!
- sandbox -X doesn't work in F13
- SELINUX in permissive mode *prevents* write access?
- gdb and avc
- consolekit, udev and noatsecure
- Selinux + ruby + httpd
- xguest for CentOS?
- xguest for CentOS?
- SELinux, Samba, & Winbind
- Questions on creating policy
- system user home
- add constraint functionality to mcstrans
- Selinux and tomcat
- Two diferent Java programs on same machine
- mcstrans: bug fix for mixed raw and translated level
- Two diferent Java programs on same machine
- Enforce the same logic on autopart shrink as on resize (#608172)
- Curious AVC for syslog-ng listening on non-standard TCP Port.
- SELinux and openswan
- sandbox -X not (longer) working
- tor: dac_override, dac_read_search, name_bind and net_bind_service
- Anaconda Redesign
- bloody links!
- node-selinux
- (take II) Don't deactivate active device before running nm-c-e (#608773)
vBulletin® v, Copyright ©2000-2013, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.