selinux.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* NTP log rotation on debian [policy addition]
@ 2005-11-30 13:22 Erich Schubert
  0 siblings, 0 replies; only message in thread
From: Erich Schubert @ 2005-11-30 13:22 UTC (permalink / raw)
  To: SELinux

Hi,
Debian needs the following addition to the NTP policy:

ifdef(`distro_debian', `
# cronjob to rotate ntp statistic files
create_dir_file(system_crond_t, ntpd_log_t)
')

Since the ntp package contains a cronjob to rotate the ntp stats file,
which are created by default. ntpd doesn't have security critical logs,
so I think it's okay to have the cronjob do that directly. I've filed a
bug report with debian
(http://bugs.debian.org/340781 ) to request they use logrotate... (but
I'm not sure if logrotate currently can handle the timestamped file
naming they use)

best regards,
Erich Schubert
-- 
     erich@(vitavonni.de|debian.org)    --    GPG Key ID: 4B3A135C     (o_
 A man doesn't know what he knows until he knows what he doesn't know. //\
   In unseren Freunden suchen wir, was uns fehlt. --- Thornton Wilder  V_/_


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2005-11-30 13:22 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2005-11-30 13:22 NTP log rotation on debian [policy addition] Erich Schubert

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).