Likewise and SELinux

How would I create using audit2allow a policy for this:

Raw Audit Messages

host=delta.whitney.net type=AVC msg=audit(1293468133.661:172): avc: denied { write } for pid=3827 comm="dbus-daemon" name=".lsassd" dev=dm-4 ino=295012 scontext=system_u:system_r:system_dbusd_t:s0 tcontext=system_u:object_r:var_lib_t:s0 tclass=sock_file

host=delta.whitney.net type=SYSCALL msg=audit(1293468133.661:172): arch=c000003e syscall=42 success=no exit=-13 a0=15 a1=7ffffab98d20 a2=6e a3=0 items=1 ppid=1 pid=3827 auid=4294967295 uid=81 gid=81 euid=81 suid=81 fsuid=81 egid=81 sgid=81 fsgid=81 tty=(none) ses=4294967295 comm="dbus-daemon" exe="/bin/dbus-daemon" subj=system_u:system_r:system_dbusd_t:s0 key=(null)

host=delta.whitney.net type=PATH msg=audit(1293468133.661:172): item=0 name=(null) inode=295012 dev=fd:04 mode=0140666 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:var_lib_t:s0

I prefer questions like this to be asked on list, or by email.

You could add a rule using audit2allow, But where is .lsassd located?

What OS?

