fedora-cosmic: mark login/nss domains permissive for Kanidm
Enforcing SELinux blocks Kanidm user resolution/authentication for sshd and friends, but no AVC is emitted (even with dontaudit disabled), so the exact allow could not be pinned. Keep the CIL allows and mark the login/nss domains permissive so Kanidm logins work. Revisit when the denial can be isolated.
This commit is contained in:
@@ -97,11 +97,19 @@ postprocess:
|
|||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
semodule -n -i /usr/share/fedora-cosmic/kanidm-unixd.cil
|
semodule -n -i /usr/share/fedora-cosmic/kanidm-unixd.cil
|
||||||
|
|
||||||
# Kanidm does not ship an SELinux policy yet; let the unixd daemons run.
|
# Kanidm ships no SELinux policy and its nss/pam path is blocked under
|
||||||
|
# enforcing for the login domains in a way we could not pin to a single
|
||||||
|
# allow (no AVC is emitted, even with dontaudit off). Keep the CIL allows
|
||||||
|
# above and mark the login/nss consumers permissive so Kanidm users can
|
||||||
|
# resolve and log in. Tradeoff: these domains are not confined.
|
||||||
- |
|
- |
|
||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
set -xeuo pipefail
|
set -xeuo pipefail
|
||||||
semanage permissive -a unconfined_service_t || true
|
for domain in sshd_t sshd_session_t sshd_auth_t chkpwd_t \
|
||||||
|
systemd_userdbd_t local_login_t xdm_t polkit_t accountsd_t \
|
||||||
|
unconfined_service_t; do
|
||||||
|
semanage permissive -a "${domain}" || true
|
||||||
|
done
|
||||||
|
|
||||||
# Lock down the Kanidm service account token if it was seeded at build time.
|
# Lock down the Kanidm service account token if it was seeded at build time.
|
||||||
- |
|
- |
|
||||||
|
|||||||
Reference in New Issue
Block a user