package shadow-4.0.18.2-1 enable pam_selinux in login.pam

Bug #191326 reported by Caleb Case
4
Affects Status Importance Assigned to Milestone
shadow (Ubuntu)
Fix Released
Undecided
Kees Cook

Bug Description

The default login.pam does not run pam_selinux and results in incorrect login contexts if SELinux is enabled on the system. We would like pam_selinux to be run by default in Hardy to facilitate supporting SELinux. Debdiff attached.

Thanks,

Caleb

DISTRIB_ID=Ubuntu
DISTRIB_RELEASE=8.04
DISTRIB_CODENAME=hardy
DISTRIB_DESCRIPTION="Ubuntu hardy (development branch)"

Source package:

shadow_4.0.18.2-1

Binary Package:

+++-==============-==============-============================================
ii login 1:4.0.18.2-1ub system login tools

Related branches

Revision history for this message
Caleb Case (calebcase) wrote :
Revision history for this message
Kees Cook (kees) wrote :

What about things like SSH and GDM? Is this something that should be added to the common pam files? Also, will these login changes behave okay if SELinux is not enabled?

Changed in shadow:
assignee: nobody → keescook
status: New → Incomplete
Revision history for this message
Caleb Case (calebcase) wrote :

pam_selinux will return success if selinux is not enabled.

SSH and GDM have their own special support for handling selinux contexts.

Kees Cook (kees)
Changed in shadow:
status: Incomplete → In Progress
Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package shadow - 1:4.0.18.2-1ubuntu1

---------------
shadow (1:4.0.18.2-1ubuntu1) hardy; urgency=low

  * debian/login.pam: Enable SELinux support in login.pam (LP: #191326).

 -- Caleb Case <email address hidden> Fri, 08 Feb 2008 02:20:06 -0500

Changed in shadow:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.