Compare commits
15 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
47267b8b95 | ||
|
|
4ddcc9cedd | ||
|
|
5b326afa43 | ||
|
|
0b591ce88f | ||
|
|
5b24bf6347 | ||
|
|
9fee5ac98d | ||
|
|
77b10e8ff7 | ||
|
|
d0e0203ac3 | ||
|
|
5bdf8a6e85 | ||
|
|
ad4708c364 | ||
|
|
704b2b845e | ||
|
|
02204f1e86 | ||
|
|
3faffef992 | ||
|
|
f9761d0752 | ||
|
|
1877a39928 |
1 changed files with 26 additions and 4 deletions
30
fail2ban.te
30
fail2ban.te
|
|
@ -99,18 +99,40 @@ logging_read_syslog_pid(fail2ban_t)
|
|||
logging_dontaudit_search_audit_logs(fail2ban_t)
|
||||
logging_mmap_generic_logs(fail2ban_t)
|
||||
logging_mmap_journal(fail2ban_t)
|
||||
gen_require(`
|
||||
type var_log_t, auditd_log_t;
|
||||
class dir { watch };
|
||||
class file { watch };
|
||||
')
|
||||
allow fail2ban_t fail2ban_log_t:file watch;
|
||||
# Not in EL9 yet
|
||||
#logging_watch_audit_log_files(fail2ban_t)
|
||||
gen_require(`
|
||||
type var_log_t, auditd_log_t;
|
||||
')
|
||||
watch_files_pattern(fail2ban_t, auditd_log_t, auditd_log_t)
|
||||
# Not in EL8
|
||||
#watch_files_pattern(fail2ban_t, auditd_log_t, auditd_log_t)
|
||||
allow fail2ban_t auditd_log_t:dir search_dir_perms;
|
||||
allow fail2ban_t auditd_log_t:file { getattr watch };
|
||||
#logging_watch_audit_log_dirs(fail2ban_t)
|
||||
allow fail2ban_t var_log_t:dir search_dir_perms;
|
||||
watch_dirs_pattern(fail2ban_t, auditd_log_t, auditd_log_t)
|
||||
logging_watch_generic_log_dirs(fail2ban_t)
|
||||
logging_watch_journal_dir(fail2ban_t)
|
||||
|
||||
# Not in EL8
|
||||
#watch_dirs_pattern(fail2ban_t, auditd_log_t, auditd_log_t)
|
||||
allow fail2ban_t auditd_log_t:dir search_dir_perms;
|
||||
allow fail2ban_t auditd_log_t:dir { getattr watch };
|
||||
|
||||
# Not in EL8
|
||||
#logging_watch_generic_log_dirs(fail2ban_t)
|
||||
files_search_var(fail2ban_t)
|
||||
allow fail2ban_t var_log_t:dir { getattr watch };
|
||||
|
||||
# Not in EL8
|
||||
#logging_watch_journal_dir(fail2ban_t)
|
||||
gen_require(`
|
||||
type syslogd_var_run_t;
|
||||
')
|
||||
allow fail2ban_t syslogd_var_run_t:dir { getattr watch };
|
||||
|
||||
mta_send_mail(fail2ban_t)
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue