fedora-cosmic: mark login/nss domains permissive for Kanidm
Enforcing SELinux blocks Kanidm user resolution/authentication for sshd and friends, but no AVC is emitted (even with dontaudit disabled), so the exact allow could not be pinned. Keep the CIL allows and mark the login/nss domains permissive so Kanidm logins work. Revisit when the denial can be isolated.
This commit is contained in:
@@ -97,11 +97,19 @@ postprocess:
|
||||
set -xeuo pipefail
|
||||
semodule -n -i /usr/share/fedora-cosmic/kanidm-unixd.cil
|
||||
|
||||
# Kanidm does not ship an SELinux policy yet; let the unixd daemons run.
|
||||
# Kanidm ships no SELinux policy and its nss/pam path is blocked under
|
||||
# enforcing for the login domains in a way we could not pin to a single
|
||||
# allow (no AVC is emitted, even with dontaudit off). Keep the CIL allows
|
||||
# above and mark the login/nss consumers permissive so Kanidm users can
|
||||
# resolve and log in. Tradeoff: these domains are not confined.
|
||||
- |
|
||||
#!/usr/bin/env bash
|
||||
set -xeuo pipefail
|
||||
semanage permissive -a unconfined_service_t || true
|
||||
for domain in sshd_t sshd_session_t sshd_auth_t chkpwd_t \
|
||||
systemd_userdbd_t local_login_t xdm_t polkit_t accountsd_t \
|
||||
unconfined_service_t; do
|
||||
semanage permissive -a "${domain}" || true
|
||||
done
|
||||
|
||||
# Lock down the Kanidm service account token if it was seeded at build time.
|
||||
- |
|
||||
|
||||
Reference in New Issue
Block a user