SELinux policy for shibd

Gerald Vogt vogt at spamcop.net
Mon Apr 1 16:24:59 UTC 2024


Hi,

for anyone who is interested in having some better selinux policies for 
shibd and not running unconfined, I have assembled a small selinux 
module for shibd:

https://github.com/gvde/selinux-shibd

I only started with this and I am currently using shibd only on 
AlmaLinux 9, thus at the moment I can only say that it's working well 
for my shibd running on AL9 and I haven't seen any avc denials since. As 
I am still testing, the shib_t type is set as permissive at the moment, 
i.e. it won't actually block access even if the system selinux state is 
enforcing.

You should get a working selinux module for EL8 as well, but it may have 
something missing. I haven't tested on EL8.

The initial policy has been generated on EL9 and then extended to cover 
configuration, logs and runtime. I have looked at the shibboleth policy 
in the selinux refpolicy but that's not in "EL9 style" and it also 
seemed overly complex for my purposes. That's why I chose this way.

I hope this is helpful. I'd love to hear feedback, in particular in 
regard to missing policy rules which I may not have found, yet.

Regards,

Gerald


More information about the users mailing list