Re: selinux is a pain



On Tue, Sep 20, 2011 at 09:31:14 -0300,
Martín Marqués <martin.marques@xxxxxxxxx> wrote:

For example, I moved the trac repos to /var/lib/trac, and so apache
needs extra append and access policy on some of those directories. How
would I add those policies?

If you move stuff around that affects the default labelling. You can use
semanage and restorecon to have the new location have the correct defaults.

Giving the web server access to stuff is risky. The level of risk and benefit
is something you need to evaluate. But you can label the new location so
that it will be accessible to the web server. This may cause issues for
other processes trying to read or write thise files. If so, you may need
to do a custom policy. The simplest thing is to use audit2allow to see
what access is needed to allow the service to run. (If done in enforcing mode
this might take a few iterations.) However you might not want to let the
web server have access to all files labelled say var_lib_t. So it may turn
out that you need to create some new labels for the specific files you
want to let the web server have access to.
--
users mailing list
users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe or change subscription options:
https://admin.fedoraproject.org/mailman/listinfo/users
Guidelines: http://fedoraproject.org/wiki/Mailing_list_guidelines



Relevant Pages

  • Your opinions please. RE Internet Application
    ... would log button presses, light activations, connections to the web server ... User1 sees only the label referring to button 1 change to "button ... pressed".(no refresh) ...
    (microsoft.public.dotnet.framework.aspnet)
  • Re: which record?
    ... Create an A record and don't add any label to get ... Note if this zone is an AD zone also, ... will not work without turning off some things in DNS and Registry. ... > to the web server too? ...
    (microsoft.public.win2000.dns)
  • Re: bind97 from /bar/log/messages....
    ... > From earlier errors I added and then removed an "A" address label ... Sometimes you just get to the point where you just want a straight-forward answer to things because you've had enough:) I'm there now myself, ... You need an address record for named server host- ns1.thought.org. ... A <ip address of web server>; OPTIONAL: this will allow users to just enter domain and go straight to the web server. ...
    (freebsd-questions)
  • Re: Label Appears but not Button
    ... I just needed to install the FrontPage extensions on the web server ... > I have an aspx file, extremely simple, it only contains a label and a ... When I view the page in IE, only the label is visible, not the ...
    (microsoft.public.dotnet.framework.aspnet)