FAQ Search Today's Posts Mark Forums Read
» Video Reviews

» Linux Archive

Linux-archive is a website aiming to archive linux email lists and to make them easily accessible for linux users/developers.


» Sponsor

» Partners

» Sponsor

Go Back   Linux Archive > Redhat > Fedora SELinux Support

 
 
LinkBack Thread Tools
 
Old 06-21-2011, 04:16 AM
Michael Milverton
 
Default Confined Users & SELinux Denials

Hi, firstly thanks for all the great work, Fedora 15 is a nice release and SELinux has come a long way since I first had a look at it. I followed Dan's instructions on confining users here: http://danwalsh.livejournal.com/18312.html. Now that I'm a 'guinea pig' should I report these denials here or somewhere else or nowhere?


The following process want read access on ld.so.cache:
setfiles, ssh-keygen, consoletype, systemd-tty-ask-password-agent, avahi-daemon, nm-dhcp-client.action smbd, ip, ip6tables-multi, nmbd

ld.so.cache is quite the desirable file apparently so whats up with this?


Thanks
Michael



--
selinux mailing list
selinux@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/selinux
 
Old 06-21-2011, 07:37 AM
Dominick Grift
 
Default Confined Users & SELinux Denials

On Tue, 2011-06-21 at 12:16 +0800, Michael Milverton wroteig'
> should I report these denials here or somewhere else or nowhere?

Yes enclose them here

> The following process want read access on ld.so.cache:
> setfiles, ssh-keygen, consoletype, systemd-tty-ask-password-agent,
> avahi-daemon, nm-dhcp-client.action smbd, ip, ip6tables-multi, nmbd
>
> ld.so.cache is quite the desirable file apparently so whats up with this?

I dont know until you show me the avc denials and anyting else relevant.

> Thanks
> Michael
> --
> selinux mailing list
> selinux@lists.fedoraproject.org
> https://admin.fedoraproject.org/mailman/listinfo/selinux
--
selinux mailing list
selinux@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/selinux
 
Old 06-21-2011, 08:53 AM
Michael Milverton
 
Default Confined Users & SELinux Denials

Thanks Dominick,
I ran restorecon on /etc just to make sure so before I bombard you with
audit messages I'll see if it just needed to be relabeled as that may be
all that it was.

On Tue, 2011-06-21 at 09:37 +0200, Dominick Grift wrote:
>
> On Tue, 2011-06-21 at 12:16 +0800, Michael Milverton wroteig'
> > should I report these denials here or somewhere else or nowhere?
>
> Yes enclose them here
>
> > The following process want read access on ld.so.cache:
> > setfiles, ssh-keygen, consoletype, systemd-tty-ask-password-agent,
> > avahi-daemon, nm-dhcp-client.action smbd, ip, ip6tables-multi, nmbd
> >
> > ld.so.cache is quite the desirable file apparently so whats up with this?
>
> I dont know until you show me the avc denials and anyting else relevant.
>
> > Thanks
> > Michael
> > --
> > selinux mailing list
> > selinux@lists.fedoraproject.org
> > https://admin.fedoraproject.org/mailman/listinfo/selinux


--
selinux mailing list
selinux@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/selinux
 
Old 06-22-2011, 08:46 AM
Miroslav Grepl
 
Default Confined Users & SELinux Denials

On 06/21/2011 08:53 AM, Michael Milverton wrote:
> Thanks Dominick,
> I ran restorecon on /etc just to make sure so before I bombard you with
> audit messages I'll see if it just needed to be relabeled as that may be
> all that it was.
Let us know if the problem still persists. If yes and you will see AVC
msgs, you can open a new bugzilla.
> On Tue, 2011-06-21 at 09:37 +0200, Dominick Grift wrote:
>> On Tue, 2011-06-21 at 12:16 +0800, Michael Milverton wroteig'
>>> should I report these denials here or somewhere else or nowhere?
>> Yes enclose them here
>>
>>> The following process want read access on ld.so.cache:
>>> setfiles, ssh-keygen, consoletype, systemd-tty-ask-password-agent,
>>> avahi-daemon, nm-dhcp-client.action smbd, ip, ip6tables-multi, nmbd
>>>
>>> ld.so.cache is quite the desirable file apparently so whats up with this?
>> I dont know until you show me the avc denials and anyting else relevant.
>>
>>> Thanks
>>> Michael
>>> --
>>> selinux mailing list
>>> selinux@lists.fedoraproject.org
>>> https://admin.fedoraproject.org/mailman/listinfo/selinux
>
> --
> selinux mailing list
> selinux@lists.fedoraproject.org
> https://admin.fedoraproject.org/mailman/listinfo/selinux

--
selinux mailing list
selinux@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/selinux
 

Thread Tools




All times are GMT. The time now is 04:25 AM.

VBulletin, Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO ©2007, Crawlability, Inc.
Copyright ©2007 - 2008, www.linux-archive.org