Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 91809 - (SELinux policy) Desktop/workstations support
Summary: (SELinux policy) Desktop/workstations support
Status: RESOLVED LATER
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Hardened (show other bugs)
Hardware: All All
: Normal enhancement (vote)
Assignee: Chris PeBenito (RETIRED)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-05-07 09:55 UTC by Lorenzo Hernández García-Hierro
Modified: 2005-09-08 16:44 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Lorenzo Hernández García-Hierro 2005-05-07 09:55:27 UTC
Hi,

After talking to Stephen (spb) for some time, mainly about the SELinux support for workstations/desktops, I've decided to take some work on this, mainly to achieve the level of usability that it might require when talking in terms of a strict policy, that is, *our* (doesn't it sound good? ;) ) base policy.

Some problems I've experienced so far, soem common between my work within Ubuntu Hardened and also now as a candidate for Gentoo developership who wants to help with Hardened Gentoo and Gentoo security work (among anything that might be required):

 - D-BUS policy files missing: problems with D-BUS:

dunruin policy-1.22 # /etc/init.d/dbus restart
Authenticating lorenzo.
Password:
 * Starting D-BUS system messagebus ...
Failed to start message bus: Failed to open "/etc/security/contexts/dbus_contexts": No such file or directory                                          [ !! ]

(Will file a bug report regarding this one later)

contexts files should be kept on /etc/security/selinux/contexts/, instead of /etc/security.

 * User handling: we must try to make it more usable, or at least take a look at gdm when you log in with an user which is not defined in /etc/security/selinux/src/policy/users, and then decide if that's what we want for a forthcoming user base.

 * SELinux support in genkernel (--lsm, --selinux), I'll work on it.

BTW, also on --grsecurity, --grsecurity-low, --grsecurity-medium, etc, --pax...
I've discovered that great and useful piece of software, my fault ;)

More coming after this week, I'll keep testing and working on my fresh Gentoo laptop with the SELInux 2005.0 profile (BTW, udev transition might need to be worked out in order to avoid all the painful process of checking for each missing device node).

Cheers, thanks in advance.
Lorenzo.
Comment 1 Chris PeBenito (RETIRED) gentoo-dev 2005-09-08 16:44:36 UTC
waiting until reference policy is ready, at a minimum