Yeah, definitely, later tonight if I have a few minutes I'll write up the exact 
steps. I imagine once you have the policy package you could probably install it 
automatically in future builds for distros with SELinux enabled.

Andy

On Jul 31, 2011, at 4:36 PM, "Tom Eastep" <[email protected]> wrote:

> 
> On Jul 31, 2011, at 11:14 AM, Andrew Silverman wrote:
> 
>> I figured out how to fix it the "right" way. :-)
>> 
>> There's a great walkthrough of analysis tools for SELinux audit logs and how 
>> to create new permissions policies from them here: 
>> http://wiki.centos.org/HowTos/SELinux#head-aa437f65e1c7873cddbafd9e9a73bbf9d102c072
>> 
>> After that, it was cookbook.  Had to do it once for Shorewall6, which worked 
>> on the first try, and then again for radvd - it was making some system call 
>> that its default policy wasn't covering for some reason.
> 
> 
> It would be great if you would share exactly what you did so everyone who 
> encounters this problem doesn't have to go through the learning curve that 
> you did.
> 
> Thanks,
> -Tom
> 
> Tom Eastep        \ When I die, I want to go like my Grandfather who
> Shoreline,         \ died peacefully in his sleep. Not screaming like
> Washington, USA     \ all of the passengers in his car
> http://shorewall.net \________________________________________________
> 
> 
> 
> ------------------------------------------------------------------------------
> Got Input?   Slashdot Needs You.
> Take our quick survey online.  Come on, we don't ask for help often.
> Plus, you'll get a chance to win $100 to spend on ThinkGeek.
> http://p.sf.net/sfu/slashdot-survey
> _______________________________________________
> Shorewall-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/shorewall-users

------------------------------------------------------------------------------
Got Input?   Slashdot Needs You.
Take our quick survey online.  Come on, we don't ask for help often.
Plus, you'll get a chance to win $100 to spend on ThinkGeek.
http://p.sf.net/sfu/slashdot-survey
_______________________________________________
Shorewall-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/shorewall-users

Reply via email to