role's holes

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

role's holes

Postby p1kus » Thu Aug 17, 2006 7:29 am

"There were 29 holes found in your RBAC configuration. These must be fixed before the RBAC system will be allowed to be enabled"

is there any way to enable RBAC, because without it there are 29+7 holes in the system and i wanted to run at first minimal policy config

p1kus
p1kus
 
Posts: 15
Joined: Tue Jul 04, 2006 7:06 am

role's holes

Postby p1kus » Fri Aug 18, 2006 2:43 am

i commented line in gradm_analyze.c
// exit(EXIT_FAILURE);
and it seems to work
p1kus
 
Posts: 15
Joined: Tue Jul 04, 2006 7:06 am

Postby sekko » Sat Aug 19, 2006 12:34 pm

This is a blind solution: you simply "close your eyes" so that you don't see the problem. You should fix your ACLs instead, that would be a real solution.
Anyway, if you want to go production with bad ALCs, there should be a special option that make gradm silent about you ACLs. Try with "gradm -E -H" (or look at the startup guide that you find in DOCS section).
sekko
 
Posts: 13
Joined: Mon Apr 05, 2004 5:52 am


Return to grsecurity support

cron