Sam Varshavchik writes:

Gordon Messmer writes:

courierlogger is set to courier_exec_t:

/etc/selinux/targeted/contexts/files/file_contexts:/usr/sbin/courierlogger
--      system_u:object_r:courier_exec_t:s0

# ls -lZ /usr/sbin/courierlogger
-rwxr-xr-x. daemon daemon system_u:object_r:courier_exec_t:s0
/usr/sbin/courierlogger

I think something treats courier_exec_t as an alias of system_mail_t,
but I don't remember where that might be defined.  I'm kind of getting
tired of filing bugs with Red Hat because they treat Courier as if it
were sendmail.

Who set this SELinux context on courierlogger? My RPMs don't do anything, selinux-wise.

Answering my own question: this configuration file is installed by Fedora's selinux package.

The file_contexts file is missing any entries for /usr/libexec/courier- authlib, where courier-authlib gets installed.

Looks to me like someone added these SELinux entries ages ago, before courier-authlib became a separate package, and nobody has maintained these entries ever since.

This whole SELinux business is just one tangled mess of a hairball. No wonder I have it disabled.

Attachment: pgp0NCDGNRHBq.pgp
Description: PGP signature

------------------------------------------------------------------------------
Don't Limit Your Business. Reach for the Cloud.
GigeNET's Cloud Solutions provide you with the tools and support that
you need to offload your IT needs and focus on growing your business.
Configured For All Businesses. Start Your Cloud Today.
https://www.gigenetcloud.com/
_______________________________________________
courier-users mailing list
courier-users@lists.sourceforge.net
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users

Reply via email to