selinux.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* RHEL auth_role using logging_send_audit_msgs
@ 2019-02-26 22:20 Ted Toth
  2019-02-27  8:21 ` Dominick Grift
  2019-02-27 13:07 ` Stephen Smalley
  0 siblings, 2 replies; 4+ messages in thread
From: Ted Toth @ 2019-02-26 22:20 UTC (permalink / raw)
  To: selinux

The RHEL version of the auth_role macro which we are getting through
our use of userdom_unpriv_user_template uses logging_send_audit_msgs
which give a type the audit_write capability and allow rules for a
number of netlink_audit_socket operations. It seem counterintuitive to
give an unprivileged user type audit write related policy.The
ref-policy version of auth_role does not use logging_send_audit_msgs.
We're considering patching our policy but I wanted to see what others
though about giving unprivileged user types this policy?

Ted

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2019-02-27 13:11 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-02-26 22:20 RHEL auth_role using logging_send_audit_msgs Ted Toth
2019-02-27  8:21 ` Dominick Grift
2019-02-27  9:39   ` Dominick Grift
2019-02-27 13:07 ` Stephen Smalley

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).