selinux-refpolicy/policy/modules/services/entropyd.fc
Topi Miettinen 1d6982b0ea
Consider jitterentropy to belong to entropyd family
Also allow jitterentropy (or rather some libs) to read
/proc/crypto/fips_enabled.

Signed-off-by: Topi Miettinen <toiwoton@gmail.com>
2020-02-12 00:00:21 +02:00

15 lines
864 B
Plaintext

/etc/rc\.d/init\.d/((audio-entropyd)|(haveged)|(jitterentropy-rngd)) -- gen_context(system_u:object_r:entropyd_initrc_exec_t,s0)
/usr/lib/systemd/system/haveged.*\.service -- gen_context(system_u:object_r:entropyd_unit_t,s0)
/usr/lib/systemd/system/jitterentropy.*\.service -- gen_context(system_u:object_r:entropyd_unit_t,s0)
/usr/bin/audio-entropyd -- gen_context(system_u:object_r:entropyd_exec_t,s0)
/usr/bin/haveged -- gen_context(system_u:object_r:entropyd_exec_t,s0)
/usr/sbin/audio-entropyd -- gen_context(system_u:object_r:entropyd_exec_t,s0)
/usr/sbin/haveged -- gen_context(system_u:object_r:entropyd_exec_t,s0)
/usr/sbin/jitterentropy-rngd -- gen_context(system_u:object_r:entropyd_exec_t,s0)
/run/audio-entropyd\.pid -- gen_context(system_u:object_r:entropyd_runtime_t,s0)
/run/haveged\.pid -- gen_context(system_u:object_r:entropyd_runtime_t,s0)