diff --git a/images/fedora-cosmic/custom.yaml b/images/fedora-cosmic/custom.yaml index 9e534ff..87377c4 100644 --- a/images/fedora-cosmic/custom.yaml +++ b/images/fedora-cosmic/custom.yaml @@ -97,11 +97,19 @@ postprocess: set -xeuo pipefail semodule -n -i /usr/share/fedora-cosmic/kanidm-unixd.cil - # Kanidm does not ship an SELinux policy yet; let the unixd daemons run. + # Kanidm ships no SELinux policy and its nss/pam path is blocked under + # enforcing for the login domains in a way we could not pin to a single + # allow (no AVC is emitted, even with dontaudit off). Keep the CIL allows + # above and mark the login/nss consumers permissive so Kanidm users can + # resolve and log in. Tradeoff: these domains are not confined. - | #!/usr/bin/env bash set -xeuo pipefail - semanage permissive -a unconfined_service_t || true + for domain in sshd_t sshd_session_t sshd_auth_t chkpwd_t \ + systemd_userdbd_t local_login_t xdm_t polkit_t accountsd_t \ + unconfined_service_t; do + semanage permissive -a "${domain}" || true + done # Lock down the Kanidm service account token if it was seeded at build time. - |