LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-21-2006, 07:14 AM   #1
rogk
Member
 
Registered: Feb 2004
Location: Finland
Distribution: Mandrake 10.0
Posts: 70

Rep: Reputation: 15
Getting started with SELinux.


Hello,
I have just started with SELinux and distro is Gentoo. What is the best way to get those base policies that you could shutdown and boot the computer in enforce mode. I shut the computer in permissive mode and then started it. Then I used audit2allow to create the policies. That's how I did it. I don't know is this the best way and are there better ways to do it.
Second question is about logging in.I can't log in when I'm in enforce mode and using staff_r role, I get this message:
"Your account has expired;please contact your system administrator."

Always when I'm logging in at permissive mode as staff_r or user_r role , I'll get these messages
"Warning! Could not get current context for /dev/tty2, not relabeling."
"Warning! Could not get current context for /dev/vcs2, not relabeling."
"Warning! Could not get current context for /dev/vcsa2, not relabeling."
Are these two things related.
I have tried to solve this with audit2allow in permissive mode and create those policies about logging.
But I don't know what is the problem here. I can log in as root with both modes.

Last edited by rogk; 01-21-2006 at 09:30 AM.
 
Old 01-24-2006, 12:34 PM   #2
rogk
Member
 
Registered: Feb 2004
Location: Finland
Distribution: Mandrake 10.0
Posts: 70

Original Poster
Rep: Reputation: 15
Hello, again

"Problems" solved, few SELinux options were missing from kernel. Now users can log in without warnings.
 
Old 01-26-2006, 07:47 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,417
Blog Entries: 55

Rep: Reputation: 3621Reputation: 3621Reputation: 3621Reputation: 3621Reputation: 3621Reputation: 3621Reputation: 3621Reputation: 3621Reputation: 3621Reputation: 3621Reputation: 3621
Cool. Which options where missing just in case someone else stumbles on this thread later on?
 
Old 01-27-2006, 11:01 AM   #4
rogk
Member
 
Registered: Feb 2004
Location: Finland
Distribution: Mandrake 10.0
Posts: 70

Original Poster
Rep: Reputation: 15
I changed my kernel to newer one, so I have missed these

[*] /dev/pts Extended Attributes
[*] /dev/pts Security Labels
[*] Virtual memory file system support (former shm fs)
[*] tmpfs Extended Attributes
[*] tmpfs Security Labels

when I did that. But now I know, that I should check very carefully everything when I do "make menuconfig".

Last edited by rogk; 01-27-2006 at 11:04 AM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
what is selinux? mesh2005 Linux - General 2 01-04-2006 11:33 AM
selinux.h ? DJ Shaji Red Hat 1 03-26-2005 12:57 PM
SELinux winxshadi76 Linux - Newbie 1 12-03-2004 11:04 AM
Selinux fedorafreak Fedora 2 08-15-2004 09:41 AM
Selinux tessx Linux - General 3 05-22-2004 12:46 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:04 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration