Re: Selinux: /bin/su and pam_selinux

Luis Ressel <[email protected]> Sat, 21 Jan 2017 20:04:14 +0100
Newsgroups gmane.linux.gentoo.hardened
Message-ID <[email protected]>
On Sat, 21 Jan 2017 18:04:51 +0000
Robert Sharp <selinux-/[email protected]> wrote:

>      type=AVC msg=audit(1485020695.038:10368): avc:  denied
> { create } for  pid=20374 comm="su"
> scontext=staff_u:sysadm_r:sysadm_su_t tcontext=root:sysadm_r:sysadm_t
> tclass=key permissive=1

I haven't looked at this in detail, so please forgive me if my answer
is utter nonsense: Have you considered that this denial might be caused
by UBAC (that's the fancy name for the restrictions refpolicy places
upon interactions between different selinux users, staff_u and root in
this case)?

Anyway, personally I've never tried making su work with SELinux.
"sudo -r sysadm_r -t sysadm_t" works like a charm.

Regards,
Luis Ressel
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEEBodceejG8DmqwH0BfuuULjDLicFAliDsK8ACgkQBfuuULjD
Lif2rg/9G/YeYbzUaBu3tmZXwOj1CWea3DyTn3DQjQzdVfHqpW+zXBPetG/Qjn9m
UBs+3jh8x8G7jIa2c3Ksf4DxtmZOPDxuk0mgX/GOfLbwPuN3MKTFsfHKOCEbCbpB
C2/y51g43ihjsKwyJN1W3iZ8DiKgVS7Rl7H2GCQzGhfgBUcNyVe/gryt8oWdo0UQ
Gh+Jiqn6otes51xyFcNdUQsOzzIfnMd7GvYF5x51HrAtIUPFHGhipscej56KeJ6f
1nmJLGftl1oJjDiijiF4MgJQwWeCMfVVE1y3iDxLZBtZO6PkMkWPr4KU+hVNjWo0
ldms9WoIL8iW1Q3vRfxTXBDb1U6QfIc4JYnie9MopDP2jCdOtorDgN5t+rSUdhtM
iLrBJoJ29N9wegCKAuu+cUv+hkB9CFpRIbb6oK+JYmEcipmIdpS41/3MzTPwv3FK
Twqw7sC9rt4FVJ94pQgVTr8O6FaKPza6QNd4Ak5zM/HdVNCtd+abtbBNVqlm7Y+i
mPFByDlVlhoGLClZmQe2PgnPngdX444FLj1xwfcYiEtermWLwMtzXB+PTMohHogR
cch+tiny7P5h7uRlITKA0i3VPPvpONI3F0WJh0CZkD3qdUG9JGT9C8UElLZqMeS3
sRYCg2U4gE4eJmSzzUoO6M5btSiPeuaKlpSF8I5vEV6BakYdXQM=
=XRBH
-----END PGP SIGNATURE-----