SELinux policy for shibd
Gerald Vogt
vogt at spamcop.net
Mon Apr 1 16:24:59 UTC 2024
Hi,
for anyone who is interested in having some better selinux policies for
shibd and not running unconfined, I have assembled a small selinux
module for shibd:
https://github.com/gvde/selinux-shibd
I only started with this and I am currently using shibd only on
AlmaLinux 9, thus at the moment I can only say that it's working well
for my shibd running on AL9 and I haven't seen any avc denials since. As
I am still testing, the shib_t type is set as permissive at the moment,
i.e. it won't actually block access even if the system selinux state is
enforcing.
You should get a working selinux module for EL8 as well, but it may have
something missing. I haven't tested on EL8.
The initial policy has been generated on EL9 and then extended to cover
configuration, logs and runtime. I have looked at the shibboleth policy
in the selinux refpolicy but that's not in "EL9 style" and it also
seemed overly complex for my purposes. That's why I chose this way.
I hope this is helpful. I'd love to hear feedback, in particular in
regard to missing policy rules which I may not have found, yet.
Regards,
Gerald
More information about the users
mailing list