From f4ae8df39d5f6158a4d783e92b0d4bfefdb9f83f Mon Sep 17 00:00:00 2001 From: Patrick Uiterwijk Date: Thu, 4 May 2017 14:12:56 +0000 Subject: Fix up policy source and add EL6 compiled version Signed-off-by: Patrick Uiterwijk --- roles/base/files/selinux/rsyslog-audit.pp | Bin 0 -> 7609 bytes roles/base/files/selinux/rsyslog-audit.te | 13 ++++--------- 2 files changed, 4 insertions(+), 9 deletions(-) create mode 100644 roles/base/files/selinux/rsyslog-audit.pp diff --git a/roles/base/files/selinux/rsyslog-audit.pp b/roles/base/files/selinux/rsyslog-audit.pp new file mode 100644 index 000000000..f1a417ff5 Binary files /dev/null and b/roles/base/files/selinux/rsyslog-audit.pp differ diff --git a/roles/base/files/selinux/rsyslog-audit.te b/roles/base/files/selinux/rsyslog-audit.te index 31f3a2221..a8bf497c2 100644 --- a/roles/base/files/selinux/rsyslog-audit.te +++ b/roles/base/files/selinux/rsyslog-audit.te @@ -1,15 +1,10 @@ module rsyslog-audit 1.0; require { - type audit_log_t; - class file search; -} - -require { - type audit_log_t; - class file ioctl; - class file open; - class file read; + type auditd_log_t; + type syslogd_t; + class file { getattr ioctl open read }; + class dir { getattr search }; } #============= syslogd_t ============== -- cgit