SELinux & apache/httpd access to /home/*/www

Stephen Smalley sds at epoch.ncsc.mil
Fri Sep 17 12:49:16 UTC 2004


On Fri, 2004-09-17 at 08:17, Cream[DONut] wrote:
> could it be this one missing?
> 
> allow httpd_t home_root_t:dir { read };

It should only require search permission to home_root_t and
user_home_dir_t in order to lookup /home/<username>/www, and then have
read permission to httpd_user_content_t.  Naturally, someone (Dan,
Russell, me, whoever) should verify that, but in the past, that was
sufficient.

-- 
Stephen Smalley <sds at epoch.ncsc.mil>
National Security Agency




More information about the fedora-selinux-list mailing list