]> git.ipfire.org Git - people/stevee/selinux-policy.git/commitdiff
fix slapd init script file context
authorDan Walsh <dwalsh@redhat.com>
Tue, 5 Apr 2011 16:27:16 +0000 (12:27 -0400)
committerDan Walsh <dwalsh@redhat.com>
Tue, 5 Apr 2011 16:27:16 +0000 (12:27 -0400)
Add dev_read_rand to ssh_*_t

policy/modules/services/ldap.fc
policy/modules/services/ssh.te

index 335fda1063b28b6f4f56bcd35358d635f3723aec..92f3475bd0d6d9aef97a02799fb730cacb3ed827 100644 (file)
@@ -2,7 +2,7 @@
 /etc/ldap/slapd\.conf  --      gen_context(system_u:object_r:slapd_etc_t,s0)
 /etc/openldap/slapd\.d(/.*)?   gen_context(system_u:object_r:slapd_db_t,s0)
 
-/etc/rc\.d/init\.d/sldap       --      gen_context(system_u:object_r:slapd_initrc_exec_t,s0)
+/etc/rc\.d/init\.d/slapd       --      gen_context(system_u:object_r:slapd_initrc_exec_t,s0)
 
 /usr/sbin/slapd                --      gen_context(system_u:object_r:slapd_exec_t,s0)
 
index 8da0601e15780f2e0aadccd40434dcde2549bed3..d7c368bcf8dd81225277ccefb801c0c0079b6c80 100644 (file)
@@ -147,6 +147,7 @@ corenet_sendrecv_ssh_client_packets(ssh_t)
 corenet_tcp_bind_generic_node(ssh_t)
 corenet_tcp_bind_all_unreserved_ports(ssh_t)
 
+dev_read_rand(ssh_t)
 dev_read_urand(ssh_t)
 
 fs_getattr_all_fs(ssh_t)
@@ -231,6 +232,7 @@ tunable_policy(`allow_ssh_keysign',`
 
        allow ssh_keysign_t sshd_key_t:file read_file_perms;
 
+       dev_read_rand(ssh_keysign_t)
        dev_read_urand(ssh_keysign_t)
 
        files_read_etc_files(ssh_keysign_t)