• Documentation (Ref Guide, User Guide, etc.), User Experience
    • The JBoss Web Server 5.0 uses the `jws5_tomcat_t` selinux domain, rather than the unconfined `tomcat_t` domain for improved security.
    • Documented as Resolved Issue
    • Hide

      sesearch -ACS -s jws5_tomcat_t -t shadow_t -c file -p read
      seinfo -tjws5_tomcat_t -x
      check no presence of unconfined_domain_type or any other *unconfined* label

      Show
      sesearch -ACS -s jws5_tomcat_t -t shadow_t -c file -p read seinfo -tjws5_tomcat_t -x check no presence of unconfined_domain_type or any other *unconfined* label

      +++ This bug was initially created as a clone of Bug #1432083 +++

      Description of problem:

      It seems tomcat_t domain is in unconfined_domain, then any process which is having tomcat_t domain can access to any file. Maybe there is a bug in policy file.

      JWS5 domain name is : jws5_tomcat_t

      There shouldn't be any unconfined_domain_type associated with jws5 domain name

            [JWS-724] jws5_tomcat_t domain shouldn't be in unconfined_domain

            We need to document this change.

            Also note that the type label for JWS5's tomcat package is jws5_tomcat_t, not tomcat9_t or other derivations.

            Coty Sutherland added a comment - We need to document this change. Also note that the type label for JWS5's tomcat package is jws5_tomcat_t, not tomcat9_t or other derivations.

            Moving from JWS 4.0.0 GA/"Ready for QA" to JWS 5.0.0 DR1/Resolved. Will verify before moving to "Ready for QA" again.

            Coty Sutherland added a comment - Moving from JWS 4.0.0 GA/"Ready for QA" to JWS 5.0.0 DR1/Resolved. Will verify before moving to "Ready for QA" again.

            The policy shipped in the zips needs to be updated as well.

            Coty Sutherland added a comment - The policy shipped in the zips needs to be updated as well.

              rhn-support-csutherl Coty Sutherland
              rhn-support-csutherl Coty Sutherland
              Jan Onderka Jan Onderka
              Tyler Kelly Tyler Kelly (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: