On Sat, Nov 12, 2016 at 10:45 AM, Robert Sharp <seli...@sharp.homelinux.org> wrote: > > There does not appear to be any specific rsyslog selinux package so I assume > it should all be syslog-related and already in the core policy (although I > cannot find it there). I also note that Red Hat has a page on setting up > Rsyslog in SELinux so I feel fairly sure it should work. It only tells you > how to change the ports, however. I am using TCP on port 514 but I don't > think I need to do anything according to RH. > > Have I missed something, done something fundamentally wrong, or just need to > add something to stop the AVCs? Not keen on blindly fixing things so I want > to know what I need to do and why before I do it. > > Thanks in anticipation, > Robert Sharp
If there is no policy package installed and there is not one in the tree, you are on your own until one is written. I would double check to ensure one exists because: 1) To the best of my knowledge, there are logging policies available, and 2) policy packages tend to be missing from DEPENDS/RDEPENDS for things in the tree on SELinux profiles. As for where is best to ask, I would recommend #gentoo-hardened for this type of question. If you have a very detailed question it is likely you will get a better response on the mailing list though most of the frequent/knowledgeable posters idle in the aforementioned IRC channel. The SELinux portion of the Gentoo Project's wiki has received a lot of development by Swift(?). I would strongly recommend reading it. It will show you the discrepancies between RedHat SELinux administration and Gentoo SELinux administration (nothing is different except everything).