#-- Start nagios_plugin_checkum.te
module nagios_plugin_checkyum 1.0.4;
require {
type usr_t;
type boot_t;
type admin_home_t;
type rpm_var_lib_t;
type tmp_t;
type rpm_var_cache_t;
type nrpe_t;
type sudo_exec_t;
type http_port_t;
type rpm_exec_t;
class capability { sys_nice audit_write };
class tcp_socket name_connect;
class file { rename execute setattr read lock create ioctl execute_no_trans write getattr unlink open };
class netlink_audit_socket { write nlmsg_relay create read };
class lnk_file read;
class dir { search read write getattr remove_name open add_name };
}
#============= nrpe_t ==============
allow nrpe_t admin_home_t:dir search;
allow nrpe_t boot_t:dir { read getattr open };
allow nrpe_t http_port_t:tcp_socket name_connect;
allow nrpe_t rpm_exec_t:file { execute getattr read open ioctl execute_no_trans };
allow nrpe_t rpm_var_cache_t:dir { search getattr };
allow nrpe_t rpm_var_cache_t:dir { write read open add_name remove_name };
allow nrpe_t rpm_var_cache_t:file { rename create unlink setattr };
allow nrpe_t rpm_var_cache_t:file { write read getattr open lock };
allow nrpe_t rpm_var_lib_t:dir add_name;
allow nrpe_t rpm_var_lib_t:dir write;
allow nrpe_t rpm_var_lib_t:dir { getattr search };
allow nrpe_t rpm_var_lib_t:file create;
allow nrpe_t rpm_var_lib_t:file write;
allow nrpe_t rpm_var_lib_t:file { read lock getattr open };
allow nrpe_t self:capability { sys_nice audit_write };
allow nrpe_t self:netlink_audit_socket { write nlmsg_relay create read };
allow nrpe_t sudo_exec_t:file { read execute open execute_no_trans };
allow nrpe_t tmp_t:dir { read write add_name remove_name };
allow nrpe_t tmp_t:file { rename setattr read lock create write getattr unlink open };
allow nrpe_t usr_t:file { read getattr open };
allow nrpe_t usr_t:lnk_file read;
#-- End nagios_plugin_checkum.te
And you'll need to add something like the following to your /etc/sudoers file
nagios ALL=(ALL) NOPASSWD: /usr/lib64/nagios/plugins/check_yum
And you need to comment out the following line in the sudores file, otherwise nrpe won't be able to parse the return
#Defaults requiretty
References