HomeDevCentral

Configure SELinux policy for Yubikeys on RedHat servers

Description

Configure SELinux policy for Yubikeys on RedHat servers

Summary:
Fedora SELinux policy offers an exemption tunable to allow a TCP connection
to external servers. This changes enables it for the bastion role.

Policy is defined in policy/modules/system/authlogin.te as is:
corenet_tcp_connect_http_port(login_pgm)

References:

This configuration block is currently no-op in production, as we don't have
any Fedora bastion currently (CentOS is used for Docker engines, but these
are not intended to get bastion role).

Reviewers: dereckson

Reviewed By: dereckson

Differential Revision: https://devcentral.nasqueron.org/D1333

Details

Provenance
derecksonAuthored on Feb 18 2018, 14:09
derecksonPushed on Feb 18 2018, 14:23
Reviewer
dereckson
Differential Revision
D1333: Configure SELinux policy for Yubikeys on RedHat servers
Parents
rOPS56797e259c05: Provision ~/.yubico/authorized_yubikeys files
Branches
Unknown
Tags
Unknown