only allow 1 port for listening

Mark elihusmails at gmail.com
Wed Aug 8 15:40:03 UTC 2007


I am new to writing policies and have been reading the reference policy
files.  I wrote a simple TCP server that listens on a port for connections.
I would like to write a policy that will only allow my program to bind to a
specific port(9999).  I looked at the reference policy and see that the
ports that programs are allowed to use is in
policy/modules/kernel/corenetwork.te.  My questions is, can I specify the
port in my programs type enforcement file so that I can make a module
instead of listing this in the kernel policy?  If so, what would the syntax
be?

Thanks in advance.

-- 
..Cheers
Mark
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/fedora-selinux-list/attachments/20070808/1ceed9c0/attachment.htm>


More information about the fedora-selinux-list mailing list