[gentoo-hardened] Questions about SELinux

2016-11-12 Thread Robert Sharp
Hi there, is this the best place to raise questions about SELinux, or would I be better trying chat? I am making a big effort to get to enforcing strict on a simple server and I am struggling a little. For example, I run Rsyslog and I have lots of AVCs concerning denied sendto's to /dev/log.

Re: [gentoo-hardened] Questions about SELinux

2016-11-12 Thread Brant Williams
Hello, Robert. Do you have the package "app-admin/setools" installed? If so, you can run "cat /var/log/audit/audit.log | audit2why" to get an explanation of why the denials occur, with suggestions for fixing them. Of course, if your system is logging AVC denials elsewhere, adjust the command acco

Re: [gentoo-hardened] Questions about SELinux

2016-11-12 Thread Jason Zaman
On Sat, Nov 12, 2016 at 04:45:23PM +, Robert Sharp wrote: > Hi there, > > is this the best place to raise questions about SELinux, or would I be > better trying chat? I am making a big effort to get to enforcing strict > on a simple server and I am struggling a little. Here is good, there i