Small SELinux issue with kdm and grub

Marko Vojinovic vvmarko at panet.co.yu
Sun Mar 8 22:39:13 UTC 2009


On Sunday 08 March 2009 23:16, Kevin Kofler wrote:
> Marko Vojinovic wrote:
> > So, does anyone understand what is going on and why?
>
> You cannot use the KDM bootloader integration with SELinux. It is disabled
> by default for a reason. The SELinux policy maintainers do not want to
> allow this by default for security reasons, so you have only 4 options:
> * disable SELinux entirely,
> * set SELinux to permissive,
> * use audit2allow to create a custom SELinux policy to allow this or
> * just turn that feature off in KDM.

I don't understand the last point. What is the feature of KDM that you talk 
about? I don't remember enabling any specific feature of KDM other than 
autologin. Is that it?

:-)
Marko




More information about the fedora-list mailing list