All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] services_shorewall.patch
@ 2009-08-28 20:27 Daniel J Walsh
  2009-09-02 12:59 ` Christopher J. PeBenito
  0 siblings, 1 reply; 9+ messages in thread
From: Daniel J Walsh @ 2009-08-28 20:27 UTC (permalink / raw)
  To: refpolicy

http://people.fedoraproject.org/~dwalsh/SELinux/F12/services_shorewall.patch


shorewall firewall policy

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [refpolicy] services_shorewall.patch
  2009-08-28 20:27 [refpolicy] services_shorewall.patch Daniel J Walsh
@ 2009-09-02 12:59 ` Christopher J. PeBenito
  0 siblings, 0 replies; 9+ messages in thread
From: Christopher J. PeBenito @ 2009-09-02 12:59 UTC (permalink / raw)
  To: refpolicy

On Fri, 2009-08-28 at 16:27 -0400, Daniel J Walsh wrote:
> http://people.fedoraproject.org/~dwalsh/SELinux/F12/services_shorewall.patch
> 
> 
> shorewall firewall policy

Merged.  Moved to admin.

-- 
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [refpolicy] services_shorewall.patch
  2009-06-23 13:13       ` Daniel J Walsh
@ 2009-06-23 13:27         ` Miroslav Grepl
  0 siblings, 0 replies; 9+ messages in thread
From: Miroslav Grepl @ 2009-06-23 13:27 UTC (permalink / raw)
  To: refpolicy

On 06/23/2009 03:13 PM, Daniel J Walsh wrote:
> On 06/23/2009 08:35 AM, Christopher J. PeBenito wrote:
>> On Mon, 2009-06-22 at 16:45 -0400, Daniel J Walsh wrote:
>>> On 06/22/2009 09:59 AM, Christopher J. PeBenito wrote:
>>>> On Mon, 2009-06-08 at 21:07 -0400, Daniel J Walsh wrote:
>>>>> http://people.fedoraproject.org/~dwalsh/SELinux/F11/services_shorewall.patch 
>>>>>
>>>>>
>>>>> Shorewall policy
>>>> I don't understand why this is written as a service.  As far as I can
>>>> tell from the documentation, its not a service; it just does iptables
>>>> configuration.
>>> I got this from someone else.   So you think it should just be added to
>>> iptables config.
>>
>> Not necessarily.  It may be sufficient to change the
>> init_daemon_domain() to init_system_domain and then moving it into admin
>> layer.
>>
>
> Miroslav wrote the domain, so I guess it is between you two.  I think 
> the init_system_domain is fine.

Right now I am testing what Chris suggests. It seems fine.

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [refpolicy] services_shorewall.patch
  2009-06-23 12:35     ` Christopher J. PeBenito
@ 2009-06-23 13:13       ` Daniel J Walsh
  2009-06-23 13:27         ` Miroslav Grepl
  0 siblings, 1 reply; 9+ messages in thread
From: Daniel J Walsh @ 2009-06-23 13:13 UTC (permalink / raw)
  To: refpolicy

On 06/23/2009 08:35 AM, Christopher J. PeBenito wrote:
> On Mon, 2009-06-22 at 16:45 -0400, Daniel J Walsh wrote:
>> On 06/22/2009 09:59 AM, Christopher J. PeBenito wrote:
>>> On Mon, 2009-06-08 at 21:07 -0400, Daniel J Walsh wrote:
>>>> http://people.fedoraproject.org/~dwalsh/SELinux/F11/services_shorewall.patch
>>>>
>>>> Shorewall policy
>>> I don't understand why this is written as a service.  As far as I can
>>> tell from the documentation, its not a service; it just does iptables
>>> configuration.
>> I got this from someone else.   So you think it should just be added to
>> iptables config.
>
> Not necessarily.  It may be sufficient to change the
> init_daemon_domain() to init_system_domain and then moving it into admin
> layer.
>

Miroslav wrote the domain, so I guess it is between you two.  I think 
the init_system_domain is fine.

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [refpolicy] services_shorewall.patch
  2009-06-22 20:45   ` Daniel J Walsh
@ 2009-06-23 12:35     ` Christopher J. PeBenito
  2009-06-23 13:13       ` Daniel J Walsh
  0 siblings, 1 reply; 9+ messages in thread
From: Christopher J. PeBenito @ 2009-06-23 12:35 UTC (permalink / raw)
  To: refpolicy

On Mon, 2009-06-22 at 16:45 -0400, Daniel J Walsh wrote:
> On 06/22/2009 09:59 AM, Christopher J. PeBenito wrote:
> > On Mon, 2009-06-08 at 21:07 -0400, Daniel J Walsh wrote:
> >> http://people.fedoraproject.org/~dwalsh/SELinux/F11/services_shorewall.patch
> >>
> >> Shorewall policy
> >
> > I don't understand why this is written as a service.  As far as I can
> > tell from the documentation, its not a service; it just does iptables
> > configuration.
> 
> I got this from someone else.   So you think it should just be added to 
> iptables config.

Not necessarily.  It may be sufficient to change the
init_daemon_domain() to init_system_domain and then moving it into admin
layer.

-- 
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [refpolicy] services_shorewall.patch
  2009-06-22 13:59 ` Christopher J. PeBenito
@ 2009-06-22 20:45   ` Daniel J Walsh
  2009-06-23 12:35     ` Christopher J. PeBenito
  0 siblings, 1 reply; 9+ messages in thread
From: Daniel J Walsh @ 2009-06-22 20:45 UTC (permalink / raw)
  To: refpolicy

On 06/22/2009 09:59 AM, Christopher J. PeBenito wrote:
> On Mon, 2009-06-08 at 21:07 -0400, Daniel J Walsh wrote:
>> http://people.fedoraproject.org/~dwalsh/SELinux/F11/services_shorewall.patch
>>
>> Shorewall policy
>
> I don't understand why this is written as a service.  As far as I can
> tell from the documentation, its not a service; it just does iptables
> configuration.
>

I got this from someone else.   So you think it should just be added to 
iptables config.

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [refpolicy] services_shorewall.patch
  2009-06-09  1:07 Daniel J Walsh
@ 2009-06-22 13:59 ` Christopher J. PeBenito
  2009-06-22 20:45   ` Daniel J Walsh
  0 siblings, 1 reply; 9+ messages in thread
From: Christopher J. PeBenito @ 2009-06-22 13:59 UTC (permalink / raw)
  To: refpolicy

On Mon, 2009-06-08 at 21:07 -0400, Daniel J Walsh wrote:
> http://people.fedoraproject.org/~dwalsh/SELinux/F11/services_shorewall.patch
> 
> Shorewall policy

I don't understand why this is written as a service.  As far as I can
tell from the documentation, its not a service; it just does iptables
configuration.

-- 
Chris PeBenito
Tresys Technology, LLC
(410) 290-1411 x150

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [refpolicy] services_shorewall.patch
@ 2009-06-09  1:07 Daniel J Walsh
  2009-06-22 13:59 ` Christopher J. PeBenito
  0 siblings, 1 reply; 9+ messages in thread
From: Daniel J Walsh @ 2009-06-09  1:07 UTC (permalink / raw)
  To: refpolicy

http://people.fedoraproject.org/~dwalsh/SELinux/F11/services_shorewall.patch

Shorewall policy

^ permalink raw reply	[flat|nested] 9+ messages in thread

* [refpolicy] services_shorewall.patch
@ 2009-05-21 14:02 Daniel J Walsh
  0 siblings, 0 replies; 9+ messages in thread
From: Daniel J Walsh @ 2009-05-21 14:02 UTC (permalink / raw)
  To: refpolicy

http://people.fedoraproject.org/~dwalsh/SELinux/F11/services_shorewall.patch

Policy for shorewall firewall.

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2009-09-02 12:59 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2009-08-28 20:27 [refpolicy] services_shorewall.patch Daniel J Walsh
2009-09-02 12:59 ` Christopher J. PeBenito
  -- strict thread matches above, loose matches on Subject: below --
2009-06-09  1:07 Daniel J Walsh
2009-06-22 13:59 ` Christopher J. PeBenito
2009-06-22 20:45   ` Daniel J Walsh
2009-06-23 12:35     ` Christopher J. PeBenito
2009-06-23 13:13       ` Daniel J Walsh
2009-06-23 13:27         ` Miroslav Grepl
2009-05-21 14:02 Daniel J Walsh

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.