Matthew Saltzman wrote:
On Tue, 4 Apr 2006, Robert Nichols wrote:
Changing file contexts is very simple. Knowing what to change a
file context _to_ in order to fix any particular denial is not so
simple. And fixing the root problem that is repeatedly causing
similar denials requires quite a bit of knowledge and analysis.
I've seen references to audit2allow that make me think this tool should
help identify what needs to be changed to fix any particular denial.
Haven't investigated in detail yet.
http://fedoraproject.org/wiki/SELinux/LoadableModules/Audit2allow
(FC5)
Paul.