Skip to content

Releases: RedHat-SP-Security/keylime-selinux

Keylime SELinux policy version - v42.1.2

09 Jul 09:16
b6362c4

Choose a tag to compare

  • Extend permissions to keyring allow rule

Keylime SELinux policy version - v42.1.1

09 Jul 07:47
bb6f409

Choose a tag to compare

  • Allow keylime_server_t itself write to keyring

Keylime SELinux policy version - v42.1.0

08 Jul 14:05
31a8e51

Choose a tag to compare

  • Remove keylime_var_log_t domain from policy

Keylime SELinux policy version - v41.1.0

20 Feb 12:13
eddc503

Choose a tag to compare

  • Dontaudit keylime_server_t search to cgroup_t. Keylime server domain dont need granted access to search cgroup directories, dont audit denials.

Keylime SELinux policy version - v40.1.0

11 Oct 07:04
31fe0dc

Choose a tag to compare

  • Allow keylime_agent_t via unix_stream_socket connect and read to systemd_homed_t.

Keylime SELinux policy version - v38.1.0

14 Aug 14:03

Choose a tag to compare

  • Keylime SELinux policy provide more restricted ports.
  • New SELinux label for ports use by keylime.
  • Allow keylime_server_t tcp connect to http_cache_port_t, mysqld_port_t and postgresql_port_t.
  • Allow the keylime_server_t domain to get the attributes of all filesystems.

Keylime SELinux policy version - 1.2.0

08 Aug 10:43
62f6815

Choose a tag to compare

Allow the keylime_server_t domain to get the attributes of all filesystems. New release is applicable just for rhel-9.3.0.

Keylime SELinux policy version - 1.1.0

17 Jul 13:12

Choose a tag to compare

Keylime SELinux policy provide more restricted ports. New SELinux label for ports use by keylime. Adding tabrmd interfaces allow unix stream socket communication and dbus communication. New release is applicable just for rhel-9.3.0.

Keylime SELinux policy version 6.4.3

20 Oct 11:33
3c23ccc

Choose a tag to compare

Test also revocation phase in test and update policy

Remove part in packit file for enabling testing
of revocation parts in test. Reorder position
of run tasks and remove task related with zeromq.
Update policy to allow keylime_agent_t socket
connection to kernel_t.

Keylime SELinux policy version - 1.0.0

20 Oct 11:49
3c23ccc

Choose a tag to compare

This is starting new format of release for keylime selinux policy. Relase is applicable for fedora distros and rhel-9.2.0.