Java Mailing List Archive

http://www.redhatconfig.com/

Home » Red Hat Enterprise Linux 5 »

[rhelv5-list] SELinux module to allow a single network port?

Chris Adams

2008-02-15

Replies:

Author LoginPost Reply
I have done some minor SELinux customizations with a module, and now I'm
trying to do something a little more complicated.

I want to allow a CGI to do a "whois" lookup. It is a perl script that
is attempting to open a TCP socket to port 43. I ran audit2allow, but I
think the generated rule allows CGIs to open outbound sockets to any
port. I'd rather just allow TCP to port 43.

I don't see a defined whois port type, and I don't know quite how to
define it myself in a module.

Help?

--
Chris Adams <cmadams@(protected)>
Systems and Network Administrator - HiWAAY Internet Services
I don't speak for anybody but myself - that's enough trouble.

_______________________________________________
rhelv5-list mailing list
rhelv5-list@(protected)
https://www.redhat.com/mailman/listinfo/rhelv5-list
©2008 redhatconfig.com - Jax Systems, LLC, U.S.A.