unconfined_u:object_r:var_log_t:s0. Does anyone know the correct context for this log file? Does anyone see a security problem with using this context on this file?
I have configured logrotate to rotate the log file /var/ossec/logs/ossec.log on a CentOS 7 system, since this file is not rotated by OSSEC itself. Rotation worked for a while, but in early October 2015, SELinux started denying the rotation of this particular log file. I suspect this change was linked to a system update that changed the SELinux policies on CentOS. I was able to re-enable log rotation by changing the context of /var/ossec/logs/ossec.log tounconfined_u:object_r:var_log_t:s0. Does anyone know the correct context for this log file? Does anyone see a security problem with using this context on this file?
--
---
You received this message because you are subscribed to the Google Groups "ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ossec-list+...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.