3505a51d76
On Arch Linux, OpenSSH installs these binary files in /usr/lib/ssh: * sftp-server (labeled with ssh_keysign_exec_t type in refpolicy) * ssh-askpass (symlink to x11-ssh-askpass) * ssh-keysign * ssh-pkcs11-helper * x11-ssh-askpass (from x11-ssh-askpass package) Label all these files but sftp-server as bin_t.
20 lines
967 B
Plaintext
20 lines
967 B
Plaintext
HOME_DIR/\.ssh(/.*)? gen_context(system_u:object_r:ssh_home_t,s0)
|
|
|
|
/etc/ssh/primes -- gen_context(system_u:object_r:sshd_key_t,s0)
|
|
/etc/ssh/ssh_host.*_key -- gen_context(system_u:object_r:sshd_key_t,s0)
|
|
|
|
/usr/bin/ssh -- gen_context(system_u:object_r:ssh_exec_t,s0)
|
|
/usr/bin/ssh-agent -- gen_context(system_u:object_r:ssh_agent_exec_t,s0)
|
|
/usr/bin/ssh-keygen -- gen_context(system_u:object_r:ssh_keygen_exec_t,s0)
|
|
|
|
/usr/lib/openssh/ssh-keysign -- gen_context(system_u:object_r:ssh_keysign_exec_t,s0)
|
|
/usr/lib/ssh/ssh-keysign -- gen_context(system_u:object_r:ssh_keysign_exec_t,s0)
|
|
|
|
/usr/libexec/openssh/ssh-keysign -- gen_context(system_u:object_r:ssh_keysign_exec_t,s0)
|
|
|
|
/usr/sbin/sshd -- gen_context(system_u:object_r:sshd_exec_t,s0)
|
|
|
|
/var/run/sshd(/.*)? gen_context(system_u:object_r:sshd_var_run_t,s0)
|
|
/var/run/sshd\.init\.pid -- gen_context(system_u:object_r:sshd_var_run_t,s0)
|
|
/var/run/sshd\.pid -- gen_context(system_u:object_r:sshd_var_run_t,s0)
|