Re: Set SELinux to allow only httpd daemon to use specific tty device

2014-05-06 Thread Daniel J Walsh
On 05/06/2014 12:03 AM, Emmanuel Noobadmin wrote: On 5/5/14, Daniel J Walsh dwa...@redhat.com wrote: Simplest would be to just use # grep usbDataCollector /var/log/audit/audit.log | audit2allow -M myhttp # semodule -i myhttp.pp This would allot httpd_t processes the ability to use

Re: Set SELinux to allow only httpd daemon to use specific tty device

2014-05-05 Thread Daniel J Walsh
On 05/04/2014 12:22 AM, Emmanuel Noobadmin wrote: Using Fedora 20 3.11.10-301.fc20.x86_64 and selinux targeted policy.29 I've a PHP application that sends data to a USB tty device e.g. /dev/usbDataCollector Unfortunately selinux is blocking this action. When set to permissive, the alert

Re: Set SELinux to allow only httpd daemon to use specific tty device

2014-05-05 Thread Emmanuel Noobadmin
On 5/5/14, Daniel J Walsh dwa...@redhat.com wrote: Simplest would be to just use # grep usbDataCollector /var/log/audit/audit.log | audit2allow -M myhttp # semodule -i myhttp.pp This would allot httpd_t processes the ability to use usb_device_t. If you really wanted to tighten it up, you

Set SELinux to allow only httpd daemon to use specific tty device

2014-05-03 Thread Emmanuel Noobadmin
Using Fedora 20 3.11.10-301.fc20.x86_64 and selinux targeted policy.29 I've a PHP application that sends data to a USB tty device e.g. /dev/usbDataCollector Unfortunately selinux is blocking this action. When set to permissive, the alert browser suggests the command: setsebool -P daemons_use_tty