Re: [gentoo-hardened] Selinux: /bin/su and pam_selinux

2017-01-21 Thread Luis Ressel
On Sat, 21 Jan 2017 18:04:51 + Robert Sharp wrote: > type=AVC msg=audit(1485020695.038:10368): avc: denied > { create } for pid=20374 comm="su" > scontext=staff_u:sysadm_r:sysadm_su_t tcontext=root:sysadm_r:sysadm_t > tclass=key permissive=1 I haven't looked at this in detail, so plea

[gentoo-hardened] Selinux: /bin/su and pam_selinux

2017-01-21 Thread Robert Sharp
Hi, I have been wrestling with a problem for some time and I cannot see what I am doing wrong. Here is an outline: AIM - to be able to su to root and switch off strict mode in case something goes wrong. I was using newrole but I kept forgetting so I am trying to use pam_selinux to change the