fedora-cosmic: mark login/nss domains permissive for Kanidm
Build containers / fedora-cosmic (rawhide) (push) Failing after 51s
Build containers / fedora-cosmic (44) (push) Successful in 11m55s
Build containers / Prune old releases (push) Successful in 25s

Enforcing SELinux blocks Kanidm user resolution/authentication for sshd and
friends, but no AVC is emitted (even with dontaudit disabled), so the exact
allow could not be pinned. Keep the CIL allows and mark the login/nss domains
permissive so Kanidm logins work. Revisit when the denial can be isolated.
This commit is contained in:
2026-09-27 21:18:05 +02:00
parent e4251f4d78
commit b9fe183da1
+10 -2
View File
@@ -97,11 +97,19 @@ postprocess:
set -xeuo pipefail
semodule -n -i /usr/share/fedora-cosmic/kanidm-unixd.cil
# Kanidm does not ship an SELinux policy yet; let the unixd daemons run.
# Kanidm ships no SELinux policy and its nss/pam path is blocked under
# enforcing for the login domains in a way we could not pin to a single
# allow (no AVC is emitted, even with dontaudit off). Keep the CIL allows
# above and mark the login/nss consumers permissive so Kanidm users can
# resolve and log in. Tradeoff: these domains are not confined.
- |
#!/usr/bin/env bash
set -xeuo pipefail
semanage permissive -a unconfined_service_t || true
for domain in sshd_t sshd_session_t sshd_auth_t chkpwd_t \
systemd_userdbd_t local_login_t xdm_t polkit_t accountsd_t \
unconfined_service_t; do
semanage permissive -a "${domain}" || true
done
# Lock down the Kanidm service account token if it was seeded at build time.
- |