list changes made to policy from default

grift dominick.grift at gmail.com
Thu Nov 29 19:48:45 UTC 2012


On Mon, 2012-11-26 at 13:29 +0000, Erik Boyer wrote:
> Hello!
> 
>  
> 
> Is there any way to list changes or additions to the policy from the
> default?
> 
> I have a server that I plan on migrating and I don’t have all of the
> changes I made to SELinux’s policy documented. It would be nice if
> there was a tool that would list what options have changes since the
> default and their current values.
> 
>  
> 
> Thanks in advance!
> 
>  
> 
>  
> 
> Thank you,
> 
> Erik Boyer
> Production / IT System Support
> 
> KUKA Toledo Production Operations, LLC
> 
>  Tel. +1 419 727-5549, Fax +1 419 729-7085, Cell 419-438-5350
> erik.boyer at ktpo.com
> www.ktpo.com
> 
> Consider the environment. If you print this email, please recycle.
> 
> This e-mail may contain confidential and/or privileged information. If
> you are not the intended recipient (or have received this e-mail in
> error) please notify the sender immediately and destroy this e-mail.
> Any unauthorized copying, disclosure or distribution of contents of
> this e-mail is strictly forbidden.

Not sure exactly but i think you can also use sediff to see the
differences between your current policy.* versus the one shipped

But that excludes some stuff

You can also use sedismod to look into any custom policy packages that
you may have installed

> 
> --
> selinux mailing list
> selinux at lists.fedoraproject.org
> https://admin.fedoraproject.org/mailman/listinfo/selinux




More information about the selinux mailing list