From b9fe183da12baa41b2f8c59af7b4f6cdc3dce80d Mon Sep 17 00:00:00 2001 From: Wesley van Tilburg Date: Sun, 27 Sep 2026 21:18:05 +0200 Subject: [PATCH] fedora-cosmic: mark login/nss domains permissive for Kanidm Enforcing SELinux blocks Kanidm user resolution/authentication for sshd and friends, but no AVC is emitted (even with dontaudit disabled), so the exact allow could not be pinned. Keep the CIL allows and mark the login/nss domains permissive so Kanidm logins work. Revisit when the denial can be isolated. --- images/fedora-cosmic/custom.yaml | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/images/fedora-cosmic/custom.yaml b/images/fedora-cosmic/custom.yaml index 9e534ff..87377c4 100644 --- a/images/fedora-cosmic/custom.yaml +++ b/images/fedora-cosmic/custom.yaml @@ -97,11 +97,19 @@ postprocess: set -xeuo pipefail semodule -n -i /usr/share/fedora-cosmic/kanidm-unixd.cil - # Kanidm does not ship an SELinux policy yet; let the unixd daemons run. + # Kanidm ships no SELinux policy and its nss/pam path is blocked under + # enforcing for the login domains in a way we could not pin to a single + # allow (no AVC is emitted, even with dontaudit off). Keep the CIL allows + # above and mark the login/nss consumers permissive so Kanidm users can + # resolve and log in. Tradeoff: these domains are not confined. - | #!/usr/bin/env bash set -xeuo pipefail - semanage permissive -a unconfined_service_t || true + for domain in sshd_t sshd_session_t sshd_auth_t chkpwd_t \ + systemd_userdbd_t local_login_t xdm_t polkit_t accountsd_t \ + unconfined_service_t; do + semanage permissive -a "${domain}" || true + done # Lock down the Kanidm service account token if it was seeded at build time. - |