PacketFence - BTS - PacketFence
View Issue Details
0001108PacketFencesecuritypublic2010-11-01 19:572012-10-19 10:35
closedwon't fix 
0001108: Re-enable SE Linux support
We should try to make it compliant with SE Linux.

Running under audit is a solution that should enable us to identify what we need to do to be able to support SELinux.
No tags attached.
has duplicate 0001143closed fgaudreault SELinux Policy 
Issue History
2010-11-01 19:57obilodeauNew Issue
2010-11-01 19:57obilodeauNote Added: 0001744
2010-12-20 11:10obilodeauRelationship addedhas duplicate 0001139
2010-12-20 11:11obilodeauRelationship deletedhas duplicate 0001139
2010-12-20 11:11obilodeauRelationship addedhas duplicate 0001143
2010-12-20 11:15obilodeauDescription Updated
2010-12-20 12:02fgaudreaultAssigned To => fgaudreault
2010-12-20 12:02fgaudreaultStatusnew => assigned
2010-12-20 12:02fgaudreaultTarget Version => 2.0.1
2010-12-20 13:21fgaudreaultNote Added: 0001795
2010-12-20 13:21fgaudreaultNote Edited: 0001795
2010-12-20 13:26fgaudreaultNote Deleted: 0001795
2010-12-20 17:09fgaudreaultNote Added: 0001796
2011-01-04 16:24fgaudreaultNote Added: 0001799
2011-01-04 16:24fgaudreaultTarget Version2.0.1 => 2.1.0
2011-03-03 15:16obilodeauTarget Version2.1.0 => +1
2011-03-03 15:18obilodeauTarget Version+1 => +2
2012-10-19 10:35fgaudreaultNote Added: 0003122
2012-10-19 10:35fgaudreaultStatusassigned => closed
2012-10-19 10:35fgaudreaultResolutionopen => won't fix
2012-10-19 10:35fgaudreaultTarget Version+2 =>

2010-11-01 19:57   
Reminder sent to: fgaudreault

You know about SE Linux?
2010-12-20 17:09   
Worked on that the entire afternoon. It seems that the policy file becomes very complex (and the software is still not working properly) even using audit2allow. Also we would need to cover all possible use cases to ensure that the software still works. This is too much time consuming for the value. I suggest we close this discussion once and for all, and not support SELinux.
2011-01-04 16:24   
Moved to further releases.
2012-10-19 10:35   
No, we will not do a profile.