
<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/css" href="http://selinuxproject.org/w/skins/common/feed.css?63"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title>Audit2allowRecipe - Revision history</title>
		<link>http://selinuxproject.org/w/?title=Audit2allowRecipe&amp;action=history</link>
		<description>Revision history for this page on the wiki</description>
		<language>en</language>
		<generator>MediaWiki 1.10.4</generator>
		<lastBuildDate>Sun, 19 May 2013 09:01:15 GMT</lastBuildDate>
		<item>
			<title>DominickGrift at 15:57, 20 June 2011</title>
			<link>http://selinuxproject.org/w/?title=Audit2allowRecipe&amp;diff=1071&amp;oldid=prev</link>
			<description>&lt;p&gt;&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 15:57, 20 June 2011&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 19:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 19:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; semodule -i local.pp&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; semodule -i local.pp&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;You can view the rules to be added in the local.te file. If you are satisfied, run the &amp;quot;semodule -i local.pp&amp;quot; command to install the module. You can mail an SELinux list, such as the [https://&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;www&lt;/del&gt;.&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;redhat&lt;/del&gt;.&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;com&lt;/del&gt;/mailman/listinfo/&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;fedora-&lt;/del&gt;selinux&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;-list &lt;/del&gt;Fedora SELinux list] or the [http://www.nsa.gov/research/selinux/list.shtml NSA SELinux mailing list], to ask for review of your module before you install it.&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;You can view the rules to be added in the local.te file. If you are satisfied, run the &amp;quot;semodule -i local.pp&amp;quot; command to install the module. You can mail an SELinux list, such as the [https://&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;admin&lt;/ins&gt;.&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;fedoraproject&lt;/ins&gt;.&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;org&lt;/ins&gt;/mailman/listinfo/selinux Fedora SELinux list] or the [http://www.nsa.gov/research/selinux/list.shtml NSA SELinux mailing list], to ask for review of your module before you install it.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;[[Category:Recipes]]&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;[[Category:Recipes]]&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Mon, 20 Jun 2011 15:57:50 GMT</pubDate>			<dc:creator>DominickGrift</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Audit2allowRecipe</comments>		</item>
		<item>
			<title>Jaxelson: added category</title>
			<link>http://selinuxproject.org/w/?title=Audit2allowRecipe&amp;diff=1001&amp;oldid=prev</link>
			<description>&lt;p&gt;added category&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 18:27, 31 August 2010&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 20:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 20:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;You can view the rules to be added in the local.te file. If you are satisfied, run the &amp;quot;semodule -i local.pp&amp;quot; command to install the module. You can mail an SELinux list, such as the [https://www.redhat.com/mailman/listinfo/fedora-selinux-list Fedora SELinux list] or the [http://www.nsa.gov/research/selinux/list.shtml NSA SELinux mailing list], to ask for review of your module before you install it.&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;You can view the rules to be added in the local.te file. If you are satisfied, run the &amp;quot;semodule -i local.pp&amp;quot; command to install the module. You can mail an SELinux list, such as the [https://www.redhat.com/mailman/listinfo/fedora-selinux-list Fedora SELinux list] or the [http://www.nsa.gov/research/selinux/list.shtml NSA SELinux mailing list], to ask for review of your module before you install it.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;[[Category:Recipes]]&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Tue, 31 Aug 2010 18:27:35 GMT</pubDate>			<dc:creator>Jaxelson</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Audit2allowRecipe</comments>		</item>
		<item>
			<title>MurrayMcAllister: text review</title>
			<link>http://selinuxproject.org/w/?title=Audit2allowRecipe&amp;diff=822&amp;oldid=prev</link>
			<description>&lt;p&gt;text review&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 09:36, 25 November 2009&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 1:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 1:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;If &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;you are getting denied &lt;/del&gt;access for something you believe should be allowed you can add rules to your policy with audit2allow.&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;If &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;SELinux is denying &lt;/ins&gt;access for something you believe should be allowed&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;, &lt;/ins&gt;you can add rules to your policy with &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;the &lt;/ins&gt;audit2allow &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;program&lt;/ins&gt;.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;First, find out if &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;you are running &lt;/del&gt;auditd&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;, you can do this with ps&lt;/del&gt;:&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;First, &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;run the &amp;quot;ps -ef | grep auditd&amp;quot; command to &lt;/ins&gt;find out if auditd &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;is running&lt;/ins&gt;:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt; &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;[root@localhost ~]&lt;/del&gt;# ps -ef | grep auditd&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt; # ps -ef | grep auditd&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; root        69     2  0 Sep26 ?        00:00:00 [kauditd]&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; root        69     2  0 Sep26 ?        00:00:00 [kauditd]&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; root      1159     1  0 Sep26 ?        00:00:00 auditd&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; root      1159     1  0 Sep26 ?        00:00:00 auditd&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;If &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;you see &lt;/del&gt;auditd running, as above, &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;you'll want to &lt;/del&gt;use the -a option with audit2allow, &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;else you'll &lt;/del&gt;use the -d option. &lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;If auditd &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;is &lt;/ins&gt;running, as &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;shown &lt;/ins&gt;above, use the &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;&amp;quot;&lt;/ins&gt;-a&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;&amp;quot; &lt;/ins&gt;option with audit2allow&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;. If it is not running&lt;/ins&gt;, use the &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;&amp;quot;&lt;/ins&gt;-d&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;&amp;quot; &lt;/ins&gt;option. &lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;The -l option &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;only &lt;/del&gt;reads denials since the last policy reload and the -M option &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;lets you create &lt;/del&gt;a module to &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;add the rule to&lt;/del&gt;. &lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;The &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;&amp;quot;&lt;/ins&gt;-l&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;&amp;quot; &lt;/ins&gt;option reads denials since the last policy reload&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;, &lt;/ins&gt;and the &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;&amp;quot;&lt;/ins&gt;-M&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;&amp;quot; &lt;/ins&gt;option &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;creates &lt;/ins&gt;a module &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;with rules &lt;/ins&gt;to &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;allow those denials&lt;/ins&gt;.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;If you have previously used a &lt;/del&gt;module name &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;you'll want to choose a new name&lt;/del&gt;. For example, if you run &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;this &lt;/del&gt;once with -M local &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;you'll &lt;/del&gt;want to &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;use &lt;/del&gt;a different name &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;next time&lt;/del&gt;, &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;like &lt;/del&gt;-M local2.&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;Do not use the &amp;quot;-M&amp;quot; option to specify the same &lt;/ins&gt;module name &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;more than once&lt;/ins&gt;. For example, if you run &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;the command below &lt;/ins&gt;once with &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;&amp;quot;&lt;/ins&gt;-M local&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;&amp;quot;, and &lt;/ins&gt;want to &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;run it again later, choose &lt;/ins&gt;a different name, &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;such as &amp;quot;&lt;/ins&gt;-M local2&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;&amp;quot;&lt;/ins&gt;.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt; &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;[root@localhost ~]&lt;/del&gt;# audit2allow -l -a -M local&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt; # audit2allow -l -a -M local&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; ******************** IMPORTANT ***********************&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; ******************** IMPORTANT ***********************&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; To make this policy package active, execute:&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; To make this policy package active, execute:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 19:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 19:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; semodule -i local.pp&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; semodule -i local.pp&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt;You can &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;take a look at &lt;/del&gt;the rules &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;that will &lt;/del&gt;be added in local.te&lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;, and if &lt;/del&gt;you are satisfied &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;you can &lt;/del&gt;run semodule -i local.pp as &lt;del style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;above&lt;/del&gt;.&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt;You can &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;view &lt;/ins&gt;the rules &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;to &lt;/ins&gt;be added in &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;the &lt;/ins&gt;local.te &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;file. If &lt;/ins&gt;you are satisfied&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;, &lt;/ins&gt;run &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;the &amp;quot;&lt;/ins&gt;semodule -i local.pp&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;&amp;quot; command to install the module. You can mail an SELinux list, such &lt;/ins&gt;as &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;the [https://www.redhat.com/mailman/listinfo/fedora-selinux-list Fedora SELinux list] or the [http://www.nsa.gov/research/selinux/list.shtml NSA SELinux mailing list], to ask for review of your module before you install it&lt;/ins&gt;.&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Wed, 25 Nov 2009 09:36:15 GMT</pubDate>			<dc:creator>MurrayMcAllister</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Audit2allowRecipe</comments>		</item>
		<item>
			<title>JoshuaBrindle: add -l to audit2allow call</title>
			<link>http://selinuxproject.org/w/?title=Audit2allowRecipe&amp;diff=687&amp;oldid=prev</link>
			<description>&lt;p&gt;add -l to audit2allow call&lt;/p&gt;

			&lt;table border='0' width='98%' cellpadding='0' cellspacing='4' style=&quot;background-color: white;&quot;&gt;
			&lt;tr&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;←Older revision&lt;/td&gt;
				&lt;td colspan='2' width='50%' align='center' style=&quot;background-color: white;&quot;&gt;Revision as of 15:04, 29 September 2009&lt;/td&gt;
			&lt;/tr&gt;
		&lt;tr&gt;&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 13:&lt;/strong&gt;&lt;/td&gt;
&lt;td colspan=&quot;2&quot; align=&quot;left&quot;&gt;&lt;strong&gt;Line 13:&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;If you have previously used a module name you'll want to choose a new name. For example, if you run this once with -M local you'll want to use a different name next time, like -M local2.&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;If you have previously used a module name you'll want to choose a new name. For example, if you run this once with -M local you'll want to use a different name next time, like -M local2.&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;-&lt;/td&gt;&lt;td style=&quot;background: #ffa; font-size: smaller;&quot;&gt; [root@localhost ~]# audit2allow -a -M local&lt;/td&gt;&lt;td&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; font-size: smaller;&quot;&gt; [root@localhost ~]# audit2allow &lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;-l &lt;/ins&gt;-a -M local&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; ******************** IMPORTANT ***********************&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; ******************** IMPORTANT ***********************&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; To make this policy package active, execute:&lt;/td&gt;&lt;td&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; font-size: smaller;&quot;&gt; To make this policy package active, execute:&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</description>
			<pubDate>Tue, 29 Sep 2009 15:04:22 GMT</pubDate>			<dc:creator>JoshuaBrindle</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Audit2allowRecipe</comments>		</item>
		<item>
			<title>JoshuaBrindle: New page: If you are getting denied access for something you believe should be allowed you can add rules to your policy with audit2allow.  First, find out if you are running auditd, you can do this ...</title>
			<link>http://selinuxproject.org/w/?title=Audit2allowRecipe&amp;diff=686&amp;oldid=prev</link>
			<description>&lt;p&gt;New page: If you are getting denied access for something you believe should be allowed you can add rules to your policy with audit2allow.  First, find out if you are running auditd, you can do this ...&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;If you are getting denied access for something you believe should be allowed you can add rules to your policy with audit2allow.&lt;br /&gt;
&lt;br /&gt;
First, find out if you are running auditd, you can do this with ps:&lt;br /&gt;
&lt;br /&gt;
 [root@localhost ~]# ps -ef | grep auditd&lt;br /&gt;
 root        69     2  0 Sep26 ?        00:00:00 [kauditd]&lt;br /&gt;
 root      1159     1  0 Sep26 ?        00:00:00 auditd&lt;br /&gt;
&lt;br /&gt;
If you see auditd running, as above, you'll want to use the -a option with audit2allow, else you'll use the -d option. &lt;br /&gt;
&lt;br /&gt;
The -l option only reads denials since the last policy reload and the -M option lets you create a module to add the rule to. &lt;br /&gt;
&lt;br /&gt;
If you have previously used a module name you'll want to choose a new name. For example, if you run this once with -M local you'll want to use a different name next time, like -M local2.&lt;br /&gt;
&lt;br /&gt;
 [root@localhost ~]# audit2allow -a -M local&lt;br /&gt;
 ******************** IMPORTANT ***********************&lt;br /&gt;
 To make this policy package active, execute:&lt;br /&gt;
 &lt;br /&gt;
 semodule -i local.pp&lt;br /&gt;
&lt;br /&gt;
You can take a look at the rules that will be added in local.te, and if you are satisfied you can run semodule -i local.pp as above.&lt;/div&gt;</description>
			<pubDate>Tue, 29 Sep 2009 14:52:54 GMT</pubDate>			<dc:creator>JoshuaBrindle</dc:creator>			<comments>http://selinuxproject.org/page/Talk:Audit2allowRecipe</comments>		</item>
	</channel>
</rss>