Bug 205332 - iscsi tools need selinux policy
iscsi tools need selinux policy
Status: CLOSED RAWHIDE
Product: Fedora
Classification: Fedora
Component: iscsi-initiator-utils (Show other bugs)
rawhide
All Linux
medium Severity high
: ---
: ---
Assigned To: Mike Christie
:
Depends On:
Blocks: FC6Blocker
  Show dependency treegraph
 
Reported: 2006-09-06 00:06 EDT by Jeremy Katz
Modified: 2012-06-26 12:08 EDT (History)
2 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2006-10-09 16:57:37 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Initial policy for iscsi (6.92 KB, application/x-compressed-tar)
2006-09-25 14:50 EDT, Daniel Walsh
no flags Details

  None (edit)
Description Jeremy Katz 2006-09-06 00:06:56 EDT
We need to have some basic amount of SELinux policy around the iscsi tools so
that the tools get transitioned into domains that can connect to the sockets,
read the config files, etc when invoked by mkinitrd with root on iscsi.

At this point, probably not going to happen for test3, but we should try to get
it in right after
Comment 1 Daniel Walsh 2006-09-25 14:50:53 EDT
Created attachment 137080 [details]
Initial policy for iscsi

If you untar this tgz and execute the following commands you can install the
policy

tar zxvf /tmp/iscsi.tgz
semodule -i iscsid.pp
restorecon /sbin/iscsid /var/run/iscsid.pid 
setenforce 0
service iscsi restart

BTW iscsid.pid should be in /var/run not /etc/iscsi  Please change.
Run your tests.  Collect avcs and send them to me.
Comment 2 Jeremy Katz 2006-09-27 13:24:49 EDT
This is in now -- I'll try to do some testing with it to see where the holes are
later

Note You need to log in before you can comment on or make changes to this bug.