diff --git a/www/html/status.html b/www/html/status.html index 2068aa9..2bc8d48 100644 --- a/www/html/status.html +++ b/www/html/status.html @@ -162,12 +162,11 @@ <h2>Policy Conversion</h2> <p> This phase of reference policy development involves the conversion of policies -from the example strict policy. We have been using the Fedora strict policy -version 1.23.2-1 as a baseline for policy conversion, which is available -on the <a href="index.php?page=download">download</a> page. Then after these policies -are added to reference policy, it can be updated to be in line with current -versions of the NSA example policy. For those who wish to contribute, here -is a listing of modules which need to be converted: +from the example strict policy. We are updating the baseline to NSA CVS. +Modules that are in the targeted policy are the first priority, and modules +in the strict policy, but not targeted are second priority. +For those who wish to contribute, here is a listing of modules which need to be +converted: </p> <table cellpadding="3" cellspacing="0" border="1"> <tbody> @@ -180,329 +179,616 @@ is a listing of modules which need to be converted: <td class="header">Assigned To</td> </tr> <tr> - <td>amanda</td> + <td>amanda *+</td> <td>amanda.te amanda.fc</td> <td></td> </tr> <tr> - <td>anaconda</td> + <td>anaconda *+</td> <td>anaconda.te anaconda.fc</td> <td></td> </tr> <tr> - <td>apache</td> + <td>amavis</td> + <td>amavis.te amavis.fc</td> + <td></td> + </tr> + <tr> + <td>apache *+</td> <td>apache.te apache.fc apache_macros.te</td> <td>Tresys</td> </tr> <tr> - <td>arpwatch</td> + <td>arpwatch *+</td> <td>arpwatch.te arpwatch.fc</td> <td></td> </tr> <tr> - <td>automount</td> + <td>asterisk</td> + <td>asterisk.te asterisk.fc</td> + <td></td> + </tr> + <tr> + <td>audio-entropy</td> + <td>audio-entropyd.te audio-entropyd.fc</td> + <td></td> + </tr> + <tr> + <td>authbind</td> + <td>authbind.te authbind.fc</td> + <td></td> + </tr> + <tr> + <td>automount +</td> <td>automount.te automount.fc</td> <td></td> </tr> - <td>bluetooth</td> + <tr> + <td>backup</td> + <td>backup.te backup.fc</td> + <td></td> + </tr> + <tr> + <td>bluetooth *+</td> <td>bluetooth.te bluetooth.fc</td> <td></td> </tr> <tr> - <td>bonobo</td> + <td>bonobo +</td> <td>bonobo.te bonobo.fc bonobo_macros.te</td> <td></td> </tr> <tr> - <td>browser</td> + <td>browser +</td> <td>mozilla.te mozilla.fc mozilla_macros.te</td> <td></td> </tr> <tr> - <td>cdrecord</td> + <td>calamaris</td> + <td>calabaris.te calamaris.fc</td> + <td></td> + </tr> + <tr> + <td>cdrecord +</td> <td>cdrecord.te cdrecord.fc cdrecord_macros.te</td> <td></td> </tr> <tr> - <td>certwatch</td> + <td>certwatch +</td> <td>certwatch.te certwatch.fc</td> <td></td> </tr> <tr> - <td>cvs</td> + <td>cipe</td> + <td>ciped.te ciped.fc</td> + <td></td> + </tr> + <tr> + <td>clamav</td> + <td>clamav.te clamav.fc</td> + <td></td> + </tr> + <tr> + <td>courier</td> + <td>courier.te courier.fc</td> + <td></td> + </tr> + <tr> + <td>cvs *+</td> <td>cvs.te cvs.fc</td> <td></td> </tr> <tr> - <td>cyrus</td> + <td>cyrus *+</td> <td>cyrus.te cyrus.fc</td> <td></td> </tr> <tr> - <td>ddcprobe</td> + <td>daemontools</td> + <td>daemontools.te daemontools.fc daemontools_macros.te</td> + <td>Tresys</td> + </tr> + <tr> + <td>dante</td> + <td>dante.te dante.fc</td> + <td></td> + </tr> + <tr> + <td>dcc</td> + <td>dcc.te dcc.fc</td> + <td></td> + </tr> + <tr> + <td>ddclient</td> + <td>ddclient.te ddclient.fc</td> + <td></td> + </tr> + <tr> + <td>ddcprobe +</td> <td>ddcprobe.te ddcprobe.fc</td> <td></td> </tr> <tr> - <td>dmidecode</td> + <td>distcc</td> + <td>distcc.te distcc.fc</td> + <td>Tresys</td> + </tr> + <tr> + <td>djbdns</td> + <td>djbdns.te djbdns.fc</td> + <td></td> + </tr> + <tr> + <td>dmidecode *+</td> <td>dmidecode.te dmidecode.fc</td> <td></td> </tr> <tr> - <td>dovecot</td> + <td>dnsmasq</td> + <td>dnsmasq.te dnsmasq.fc</td> + <td></td> + </tr> + <tr> + <td>dpkg</td> + <td>dpkg.te dpkg.fc</td> + <td></td> + </tr> + <tr> + <td>dovecot *+</td> <td>dovecot.te dovecot.fc</td> <td></td> </tr> <tr> - <td>ethereal</td> + <td>ethereal +</td> <td>ethereal.te ethereal.fc ethereal_macros.te</td> <td></td> </tr> <tr> - <td>fetchmail</td> + <td>evolution +</td> + <td>evolution.te evolution.fc evolution_macros.te</td> + <td></td> + </tr> + <tr> + <td>fetchmail +</td> <td>fetchmail.te fetchmail.fc</td> <td></td> </tr> <tr> - <td>finger</td> + <td>finger *+</td> <td>fingerd.te fingerd.fc fingerd_macros.te</td> <td></td> </tr> <tr> - <td>fontconfig</td> + <td>fontconfig +</td> <td>fontconfig.te fontconfig.fc</td> <td></td> </tr> <tr> - <td>ftp</td> + <td>ftp *+</td> <td>ftpd.te ftpd.fc</td> <td></td> </tr> <tr> - <td>gconf</td> + <td>gatekeeper</td> + <td>gatekeeper.te gatekeeper.fc</td> + <td></td> + </tr> + <tr> + <td>gconf +</td> <td>gconf.te gconf.fc gconf_macros.te</td> <td></td> </tr> <tr> - <td>games</td> + <td>games +</td> <td>games.te games.fc games_domain.te</td> <td></td> </tr> <tr> - <td>gnome</td> + <td>gift</td> + <td>gift.te gift.fc gift_macros.te</td> + <td></td> + </tr> + <tr> + <td>gnome +</td> <td>gnome.te gnome.fc gnome_macros.te gnome_vfs.te gnome_vfs.fc gnome_vfs_macros.te gnome-pty-helper.te gnome-pty-helper.fc gph_macros.te</td> <td></td> </tr> <tr> - <td>iceauth</td> + <td>iceauth +</td> <td>iceauth.te iceauth.fc iceauth_macros ice_macros.te(?)</td> <td></td> </tr> <tr> - <td>irc</td> + <td>imazesrv</td> + <td>imazesrv.te imazesrv.fc</td> + <td></td> + </tr> + <tr> + <td>irc +</td> <td>irc.te irc.fc irc_macros.te</td> <td></td> </tr> <tr> - <td>irqbalance</td> + <td>ircd</td> + <td>ircd.te ircd.fc</td> + <td></td> + </tr> + <tr> + <td>irqbalance +</td> <td>irqbalance.te irqbalance.fc</td> <td></td> </tr> <tr> - <td>java</td> + <td>jabber</td> + <td>jabberd.te jabberd.fc</td> + <td></td> + </tr> + <tr> + <td>java +</td> <td>java.te java.fc java_macros.te</td> <td></td> </tr> <tr> - <td>kudzu</td> + <td>kudzu *+</td> <td>kudzu.te kudzu.fc</td> <td></td> </tr> <tr> - <td>lockdev</td> + <td>lcd</td> + <td>lcd.te lcd.fc</td> + <td></td> + </tr> + <tr> + <td>lockdev +</td> <td>lockdev.te lockdev.fc lockdev_macros.te</td> <td></td> </tr> <tr> - <td>mailman</td> + <td>lrr</td> + <td>lrrd.te lrrd.fc</td> + <td></td> + </tr> + <tr> + <td>mailman *+</td> <td>mailman.te mailman.fc</td> <td></td> </tr> <tr> - <td>mplayer</td> + <td>monop</td> + <td>monopd.te monopd.fc</td> + <td></td> + </tr> + <tr> + <td>mplayer +</td> <td>mplayer.te mplayer.fc mplayer_macros.te</td> <td></td> </tr> <tr> - <td>mrtg</td> + <td>mrtg +</td> <td>mrtg.te mrtg.fc</td> <td></td> </tr> <tr> - <td>openct</td> + <td>nagios</td> + <td>nagios.te nagios.fc nrpe.te nrpe.fc</td> + <td></td> + </tr> + <tr> + <td>nessus</td> + <td>nessusd.te nessusd.fc</td> + <td></td> + </tr> + <tr> + <td>networkmanager *+</td> + <td>NetworkManager.te NetworkManager.fc</td> + <td></td> + </tr> + <tr> + <td>nsd</td> + <td>nsd.te nsd.fc</td> + <td></td> + </tr> + <tr> + <td>nx</td> + <td>nx_server.te nx_server.fc</td> + <td></td> + </tr> + <tr> + <td>oav-update</td> + <td>oav-update.te oav-update.fc</td> + <td></td> + </tr> + <tr> + <td>openca</td> + <td>openca-ca.te openca-ca.fc</td> + <td></td> + </tr> + <tr> + <td>openct +</td> <td>openct.te openct.fc</td> <td></td> </tr> <tr> - <td>orbit</td> + <td>orbit +</td> <td>orbit.te orbit.fc orbit_macros.te</td> <td></td> </tr> <tr> - <td>postfix</td> + <td>perdition</td> + <td>perdition.te perdition.fc</td> + <td></td> + </tr> + <tr> + <td>portslave</td> + <td>portslave.te portslave.fc</td> + <td></td> + </tr> + <tr> + <td>postfix +</td> <td>postfix.te postfix.fc</td> <td></td> </tr> <tr> - <td>ppp</td> + <td>ppp *+</td> <td>pppd.te pppd.fc</td> <td></td> </tr> <tr> - <td>prelink</td> + <td>prelink +</td> <td>prelink.te prelink.fc</td> <td></td> </tr> <tr> - <td>print</td> + <td>print *+</td> <td>cups.te cups.fc lpd.te lpd.fc lpr_macros.te</td> <td>Tresys</td> </tr> <tr> - <td>procmail</td> + <td>procmail +</td> <td>procmail.te procmail.fc</td> <td></td> </tr> <tr> - <td>radius</td> + <td>publicfile</td> + <td>publicfile.te publicfile.fc</td> + <td></td> + </tr> + <tr> + <td>pxe</td> + <td>pxe.te pxe.fc</td> + <td></td> + </tr> + <tr> + <td>pyzor</td> + <td>pyzor.te pyzor.fc</td> + <td></td> + </tr> + <tr> + <td>radius *+</td> <td>radius.te radius.fc</td> <td></td> </tr> <tr> - <td>radvd</td> + <td>radvd *+</td> <td>radvd.te radvd.fc</td> <td></td> </tr> <tr> - <td>rlogin</td> + <td>razor</td> + <td>razor.te razor.fc</td> + <td></td> + </tr> + <tr> + <td>rdisc</td> + <td>rdisc.te rdisc.fc</td> + <td></td> + </tr> + <tr> + <td>resmgr</td> + <td>resmgrd.te resmgrd.fc</td> + <td></td> + </tr> + <tr> + <td>rlogin *+</td> <td>rlogind.te rlogind.fc login_macros.te</td> <td>Tresys</td> </tr> <tr> - <td>sasl</td> + <td>rpc *+</td> + <td>rpcd.te rpcd.fc</td> + <td></td> + </tr> + <tr> + <td>rssh</td> + <td>rssh.te rssh.fc</td> + <td></td> + </tr> + <tr> + <td>sasl *+</td> <td>saslauthd.te saslauthd.fc</td> <td></td> </tr> <tr> - <td>screen</td> + <td>scannerdaemon</td> + <td>scannerdaemon.te scannerdaemon.fc</td> + <td></td> + </tr> + <tr> + <td>screen +</td> <td>screen.te screen.fc screen_macros.te</td> <td></td> </tr> <tr> - <td>slocate</td> + <td>slocate +</td> <td>slocate.te slocate.fc slocate_macros.te</td> <td></td> </tr> <tr> - <td>slrnpull</td> + <td>slrnpull +</td> <td>slrnpull.te slrnpull.fc</td> <td></td> </tr> <tr> - <td>sound</td> - <td>alsa.te alsa.fc sound.te sound.fc</td> + <td>snort</td> + <td>snort.te snort.fc</td> + <td></td> + </tr> + <tr> + <td>sound +</td> + <td>alsa.te alsa.fc sound.te sound.fc sound-server.te sound-server.fc</td> <td></td> </tr> <tr> - <td>spamassassin</td> + <td>spamassassin +</td> <td>spamassassin.te spamc.te spamd.te spamassassin.fc spamc.fc spamd.fc spamassassin_macros.te</td> <td></td> </tr> <tr> - <td>stunnel</td> + <td>speedtouch</td> + <td>speedmgmt.te speedmgmt.fc</td> + <td></td> + </tr> + <tr> + <td>stunnel *+</td> <td>stunnel.te stunnel.fc</td> <td></td> </tr> <tr> - <td>sysstat</td> + <td>sxid</td> + <td>sxid.te sxid.fc</td> + <td></td> + </tr> + <tr> + <td>sysstat +</td> <td>sysstat.te sysstat.fc</td> <td></td> </tr> <tr> - <td>telnet</td> + <td>telnet *+</td> <td>telnetd.te telnetd.fc</td> <td></td> </tr> <tr> - <td>thunderbird</td> + <td>thunderbird +</td> <td>thunderbird.te thunderbird.fc thunderbird_macros.te mail_client_macros.te</td> <td></td> </tr> <tr> - <td>timidity</td> + <td>timidity +</td> <td>timidity.te timidity.fc</td> <td></td> </tr> <tr> - <td>tvtime</td> + <td>tinydns</td> + <td>tinydns.te tinydns.fc</td> + <td></td> + </tr> + <tr> + <td>transproxy</td> + <td>transproxy.te transproxy.fc</td> + <td></td> + </tr> + <tr> + <td>tripwire</td> + <td>tripwire.te tripwire.fc</td> + <td></td> + </tr> + <tr> + <td>tvtime +</td> <td>tvtime.te tvtime.fc tvtime_macros.te</td> <td></td> </tr> <tr> - <td>uml</td> - <td>uml.te uml.fc uml_macros.te</td> + <td>ucspi-tcp</td> + <td>ucspi-tcp.te ucspi-tcp.fc</td> <td></td> </tr> <tr> - <td>userhelper</td> + <td>uml +</td> + <td>uml.te uml.fc uml_macros.te uml_net.te uml_net.fc</td> + <td></td> + </tr> + <tr> + <td>uptimed</td> + <td>uptimed.te uptimed.fc</td> + <td></td> + </tr> + <tr> + <td>userhelper +</td> <td>userhelper.te userhelper.fc userhelper_macros.te</td> <td></td> </tr> <tr> - <td>usernetctl</td> + <td>usernetctl +</td> <td>usernetctl.te usernetctl.fc</td> <td></td> </tr> <tr> - <td>uucp</td> + <td>uucp *+</td> <td>uucpd.te uucpd.fc</td> <td></td> </tr> <tr> - <td>vmware</td> + <td>uwimap</td> + <td>uwimapd.te uwimapd.fc</td> + <td></td> + </tr> + <tr> + <td>vmware +</td> <td>vmware.te vmware.fc vmware_macros.te</td> <td></td> </tr> <tr> - <td>vpn</td> - <td>vpnc.te vpnc.fc</td> + <td>vpn +</td> + <td>vpnc.te vpnc.fc openvpn.te openvpn.fc/td> + <td></td> + </tr> + <tr> + <td>watchdog</td> + <td>watchdog.te watchdog.fc</td> <td></td> </tr> <tr> - <td>webalizer</td> + <td>webalizer *+</td> <td>webalizer.te webalizer.fc</td> <td></td> </tr> <tr> - <td>winbind</td> + <td>winbind *+</td> <td>winbind.te winbind.fc</td> <td></td> </tr> <tr> - <td>xdm</td> + <td>xdm *+</td> <td>xdm.te xdm.fc xdm_macros.te</td> <td></td> </tr> <tr> - <td>xfs</td> + <td>xfs +</td> <td>xfs.te xfs.fc</td> <td></td> </tr> <tr> - <td>xserver</td> + <td>xprint</td> + <td>xprint.te xprint.fc</td> + <td></td> + </tr> + <tr> + <td>xserver +</td> <td>xserver.te xserver.fc xserver_macros.te xauth.te xauth.fc xauth_macros.te</td> <td></td> </tr> + <tr> + <td>yam</td> + <td>yam.te yam.fc</td> + <td></td> + </tr> + <tr> + <td colspan="3">(*) Modules in the Fedora targeted policy</td> + </tr> + <tr> + <td colspan="3">(+) Modules in the Fedora strict policy</td> + </tr> </tbody> </table> <h2>Testing Status</h2>