Email - dovecot-local-1.1.te (SELinux module)
Email Solution · Config document · referenced from Virtual machines and OS build
A local SELinux type-enforcement module for Dovecot. It lets Dovecot create and write mailboxes in a directory that carries the default label, and lets the authentication process create a symbolic link in its temporary directory.
| Item | Value |
|---|---|
| Path on the server | /etc/selinux/dovecot-local-1.1.te |
| Shown here | DC2-A-VCMSX001 |
| Also on | DC2-B-VCMSX001 and DC2-A-VCMSX002, identical |
| Compiled with | checkmodule -M -m, then semodule_package; the install notes show the commands for version 1.0 only |
| Loaded with | semodule -i |
| SELinux mode | enforcing, targeted policy |
The file
module dovecot-local-1.1 1.1; require { type dovecot_t; type default_t; type nfs_t; type dovecot_auth_t; type dovecot_auth_tmp_t; class dir { add_name create remove_name write }; class file { append create getattr lock open read unlink write }; class lnk_file create; } #============= dovecot_t ============== #!!!! This avc is allowed in the current policy allow dovecot_t default_t:dir { add_name create remove_name write }; allow dovecot_t default_t:file unlink; #!!!! This avc is allowed in the current policy allow dovecot_t default_t:file { append create getattr lock open read write }; #!!!! This avc is allowed in the current policy allow dovecot_t nfs_t:dir write; #============= dovecot_auth_t ============== allow dovecot_auth_t dovecot_auth_tmp_t:lnk_file create;
The lines beginning with #!!!! were written by audit2allow, not by me: it adds them when a rule it is asked to generate is already allowed by the loaded policy, here by version 1.0 of this same module.
Differences between versions
| Where | Module line | What is different |
|---|---|---|
| Install notes of all three servers, design documents | module dovecot-local 1.0; in /etc/selinux/dovecot-local.te | Only the dovecot_t rules; no dovecot_auth_t, no lnk_file class |
| Archived configuration, all three servers | module dovecot-local-1.1 1.1; in /etc/selinux/dovecot-local-1.1.te | Adds allow dovecot_auth_t dovecot_auth_tmp_t:lnk_file create; |
The Source material does not say when or why version 1.1 was made, and it holds no commands for building it.
Checked against RHEL 10.2
| As built | Today |
|---|---|
.te compiled with checkmodule -M -m, packaged with semodule_package, loaded with semodule -i | Still works; checkpolicy and policycoreutils are shipped. The Red Hat SELinux guide for RHEL 10 no longer shows checkmodule: it shows audit2allow -M <name> followed by semodule -X 300 -i <name>.pp, and local modules written as .cil files that semodule -i loads directly |
| A local module with its own rules | Red Hat states that custom modules with own rules are outside the support scope |
The type names used in the module (dovecot_auth_tmp_t among them) were not checked against the current policy.