Logging Denials
"Sean Hogan" <[email protected]>
| Newsgroups | gmane.linux.redhat.fedora.selinux |
|---|---|
| Message-ID | <OF07DF5E42.C18D167E-ON072582B9.0072B7EA-072582B9.00736313@notes.na.collabserv.com> |
Hello,
I am not sure this use case has come up before but some our systems are
set permissive. I have 3 files I want to have shared with 644 on purpose.
The goal is for selinux to allow users(permissive) to read the file but I
need a context that will still report an AVC to audit.log as that will be
forwarded to a SIEM where rules will be in place to contact security. I
have tried auditd_etc_t, var_log_t but nothing ever shows up in audit.log
when watching a user cat/vi the files.
In this situation I actually want to see denials lol but not 100% I am
seeing this right. Any help is appreciated.
-rw-r--r--. root root unconfined_u:object_r:auditd_etc_t:s0 fil1.pgp
-rw-r--r--. root root unconfined_u:object_r:auditd_etc_t:s0 file2.docx
-rw-r--r--. root root unconfined_u:object_r:var_log_t:s0 file3.docx
Sean Hogan
_______________________________________________
selinux mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]/message/CAN2DYGIQSEYD3B6WMUFKL5HKBNUENJO/