Bug 845200 - Incorrect default label on /etc/openldap/cacerts and /etc/openldap/certs
Incorrect default label on /etc/openldap/cacerts and /etc/openldap/certs
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: selinux-policy (Show other bugs)
All Linux
medium Severity medium
: rc
: ---
Assigned To: Miroslav Grepl
BaseOS QE Security Team
Depends On:
  Show dependency treegraph
Reported: 2012-08-02 04:35 EDT by David Spurek
Modified: 2015-03-02 00:27 EST (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2012-08-06 04:26:31 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description David Spurek 2012-08-02 04:35:52 EDT
Description of problem:
Incorrect default label on /etc/openldap/cacerts and  /etc/openldap/certs.
Thel label should be slapd_cert_t, but now is:

matchpathcon /etc/openldap/cacerts
/etc/openldap/certs	system_u:object_r:etc_t:s0

Version-Release number of selected component (if applicable):

How reproducible:

Actual results:
matchpathcon /etc/openldap/cacerts
/etc/openldap/certs	system_u:object_r:etc_t:s0

Expected results:
matchpathcon /etc/openldap/cacerts
/etc/openldap/certs	system_u:object_r:slapd_cert_t:s0

Additional info:
Comment 1 RHEL Product and Program Management 2012-08-02 04:48:12 EDT
This request was evaluated by Red Hat Product Management for inclusion
in a Red Hat Enterprise Linux release.  Product Management has
requested further review of this request by Red Hat Engineering, for
potential inclusion in a Red Hat Enterprise Linux release for currently
deployed products.  This request is not yet committed for inclusion in
a release.
Comment 2 Milos Malik 2012-08-02 05:29:46 EDT
# sesearch -s slapd_t -t slapd_cert_t --allow -C
Found 3 av rules:
   allow slapd_t slapd_cert_t : file { ioctl read getattr lock }; 
   allow slapd_t slapd_cert_t : dir { ioctl read getattr lock search }; 
   allow slapd_t slapd_cert_t : lnk_file { read getattr }; 

Comment 3 Miroslav Grepl 2012-08-03 02:18:46 EDT
What does

# rpm -qf /etc/openldap
# rpm -qf /etc/openldap/certs
Comment 4 Milos Malik 2012-08-03 03:57:08 EDT
# rpm -qf /etc/openldap
# rpm -qf /etc/openldap/cacerts
Comment 5 Miroslav Grepl 2012-08-06 04:26:31 EDT
I would stay with etc_t for RHEL5 and fix it in RHEL6, RHEL7.

Note You need to log in before you can comment on or make changes to this bug.