Bug 845200 - Incorrect default label on /etc/openldap/cacerts and /etc/openldap/certs
Summary: Incorrect default label on /etc/openldap/cacerts and /etc/openldap/certs
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: selinux-policy
Version: 5.8
Hardware: All
OS: Linux
medium
medium
Target Milestone: rc
: ---
Assignee: Miroslav Grepl
QA Contact: BaseOS QE Security Team
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2012-08-02 08:35 UTC by David Spurek
Modified: 2015-03-02 05:27 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-08-06 08:26:31 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description David Spurek 2012-08-02 08:35:52 UTC
Description of problem:
Incorrect default label on /etc/openldap/cacerts and  /etc/openldap/certs.
Thel label should be slapd_cert_t, but now is:

matchpathcon /etc/openldap/cacerts
/etc/openldap/certs	system_u:object_r:etc_t:s0


Version-Release number of selected component (if applicable):
selinux-policy-2.4.6-330.el5


How reproducible:
always

Actual results:
matchpathcon /etc/openldap/cacerts
/etc/openldap/certs	system_u:object_r:etc_t:s0

Expected results:
matchpathcon /etc/openldap/cacerts
/etc/openldap/certs	system_u:object_r:slapd_cert_t:s0

Additional info:

Comment 1 RHEL Program Management 2012-08-02 08:48:12 UTC
This request was evaluated by Red Hat Product Management for inclusion
in a Red Hat Enterprise Linux release.  Product Management has
requested further review of this request by Red Hat Engineering, for
potential inclusion in a Red Hat Enterprise Linux release for currently
deployed products.  This request is not yet committed for inclusion in
a release.

Comment 2 Milos Malik 2012-08-02 09:29:46 UTC
# sesearch -s slapd_t -t slapd_cert_t --allow -C
Found 3 av rules:
   allow slapd_t slapd_cert_t : file { ioctl read getattr lock }; 
   allow slapd_t slapd_cert_t : dir { ioctl read getattr lock search }; 
   allow slapd_t slapd_cert_t : lnk_file { read getattr }; 

#

Comment 3 Miroslav Grepl 2012-08-03 06:18:46 UTC
What does

# rpm -qf /etc/openldap
# rpm -qf /etc/openldap/certs

Comment 4 Milos Malik 2012-08-03 07:57:08 UTC
# rpm -qf /etc/openldap
openldap-2.3.43-25.el5_8.1
# rpm -qf /etc/openldap/cacerts
openldap-2.3.43-25.el5_8.1
#

Comment 5 Miroslav Grepl 2012-08-06 08:26:31 UTC
I would stay with etc_t for RHEL5 and fix it in RHEL6, RHEL7.


Note You need to log in before you can comment on or make changes to this bug.