Blame refpolicy/policy/modules/system/authlogin.te
|
Chris PeBenito |
3ba13b |
########################################
|
|
Chris PeBenito |
3ba13b |
#
|
|
Chris PeBenito |
3ba13b |
# Declarations
|
|
Chris PeBenito |
3ba13b |
#
|
|
Chris PeBenito |
3ba13b |
type chkpwd_exec_t;
|
|
Chris PeBenito |
3ba13b |
domain_make_entrypoint_file(system_chkpwd_t,chkpwd_exec_t)
|
|
Chris PeBenito |
3ba13b |
|
|
Chris PeBenito |
3ba13b |
type faillog_t;
|
|
Chris PeBenito |
3ba13b |
logging_make_log_file(faillog_t)
|
|
Chris PeBenito |
3ba13b |
|
|
Chris PeBenito |
b4cd15 |
type lastlog_t;
|
|
Chris PeBenito |
b4cd15 |
logging_make_log_file(lastlog_t)
|
|
Chris PeBenito |
b4cd15 |
|
|
Chris PeBenito |
3ba13b |
type login_exec_t;
|
|
Chris PeBenito |
3ba13b |
files_make_file(login_exec_t)
|
|
Chris PeBenito |
3ba13b |
|
|
Chris PeBenito |
3ba13b |
type pam_t;
|
|
Chris PeBenito |
3ba13b |
domain_make_domain(pam_t)
|
|
Chris PeBenito |
3ba13b |
|
|
Chris PeBenito |
3ba13b |
type pam_tmp_t;
|
|
Chris PeBenito |
3ba13b |
files_make_file(pam_tmp_t)
|
|
Chris PeBenito |
3ba13b |
|
|
Chris PeBenito |
3ba13b |
type pam_var_console_t;
|
|
Chris PeBenito |
3ba13b |
files_make_file(pam_var_console_t)
|
|
Chris PeBenito |
3ba13b |
|
|
Chris PeBenito |
3ba13b |
type pam_var_run_t;
|
|
Chris PeBenito |
3ba13b |
files_make_file(pam_var_run_t)
|
|
Chris PeBenito |
3ba13b |
|
|
Chris PeBenito |
3ba13b |
type shadow_t;
|
|
Chris PeBenito |
3ba13b |
files_make_file(shadow_t)
|
|
Chris PeBenito |
3ba13b |
attribute can_read_shadow_passwords;
|
|
Chris PeBenito |
3ba13b |
attribute can_write_shadow_passwords;
|
|
Chris PeBenito |
3ba13b |
neverallow ~can_read_shadow_passwords shadow_t:file read;
|
|
Chris PeBenito |
3ba13b |
neverallow ~can_write_shadow_passwords shadow_t:file write;
|
|
Chris PeBenito |
3ba13b |
|
|
Chris PeBenito |
3ba13b |
type utempter_t;
|
|
Chris PeBenito |
3ba13b |
domain_make_domain(utempter_t)
|
|
Chris PeBenito |
3ba13b |
|
|
Chris PeBenito |
3ba13b |
type utempter_exec_t;
|
|
Chris PeBenito |
3ba13b |
domain_make_entrypoint_file(utempter_t,utempter_exec_t)
|
|
Chris PeBenito |
3ba13b |
|
|
Chris PeBenito |
b4cd15 |
type wtmp_t;
|
|
Chris PeBenito |
b4cd15 |
logging_make_log_file(wtmp_t)
|
|
Chris PeBenito |
3ba13b |
|
|
Chris PeBenito |
3ba13b |
########################################
|
|
Chris PeBenito |
3ba13b |
#
|
|
Chris PeBenito |
3ba13b |
# Local policy
|
|
Chris PeBenito |
3ba13b |
#
|
|
Chris PeBenito |
3ba13b |
authlogin_per_userdomain_template(system)
|
|
Chris PeBenito |
3ba13b |
#dontaudit system_chkpwd_t { user_tty_type tty_device_t }:chr_file rw_file_perms;
|
|
Chris PeBenito |
3ba13b |
#dontaudit system_chkpwd_t privfd:fd use;
|