Uploaded image for project: 'JBoss Web Server'
  1. JBoss Web Server
  2. JWS-1361

[RFE] Asking for "tomcat_can_network_connect_db" boolean

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Blocker Blocker
    • 5.2.0.DR1
    • JWS 5.0_RHEL_GA, 5.1.0.GA
    • selinux
    • None
    • 16
    • +

      The jws5_tomcat_domain does not apply to the selinux boolean `tomcat_can_network_connect_db`. The jws5-tomcat-selinux package should have a similar policy to the RHEL Tomcat counterpart.

      # sesearch -b tomcat_can_network_connect_db -AC
        Found 10 semantic av rules:
        DT allow tomcat_domain mssql_port_t : tcp_socket name_connect ; [ tomcat_can_network_connect_db ]
        DT allow tomcat_domain oracle_client_packet_t : packet recv ; [ tomcat_can_network_connect_db ]
        DT allow tomcat_domain oracle_client_packet_t : packet send ; [ tomcat_can_network_connect_db ]
        DT allow tomcat_domain postgresql_port_t : tcp_socket name_connect ; [ tomcat_can_network_connect_db ]
        DT allow tomcat_domain mssql_client_packet_t : packet recv ; [ tomcat_can_network_connect_db ]
        DT allow tomcat_domain mssql_client_packet_t : packet send ; [ tomcat_can_network_connect_db ]
        DT allow tomcat_domain mysqld_port_t : tcp_socket name_connect ; [ tomcat_can_network_connect_db ]
        DT allow tomcat_domain mongod_port_t : tcp_socket name_connect ; [ tomcat_can_network_connect_db ]
        DT allow tomcat_domain oracle_port_t : tcp_socket name_connect ; [ tomcat_can_network_connect_db ]
        DT allow tomcat_domain gds_db_port_t : tcp_socket name_connect ; [ tomcat_can_network_connect_db ]
      

            rhn-support-csutherl Coty Sutherland
            rhn-support-hpham Hung Pham (Inactive)
            Jan Onderka Jan Onderka
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: