Need to introduce a new SELinux type for the 389-admin package's stop-ds-admin/start-ds-admin scripts to get httpd running as httpd_t.
---
From conversation with Miroslav Grepl
type dirsrvadmin_initrc_exec_t;
init_script_file(dirsrvadmin_initrc_exec_t)
$ ls -lZ /usr/sbin/start-ds-admin
-rwxr-xr-x. root root system_u:object_r:dirsrvadmin_initrc_exec_t:s0
/usr/sbin/start-ds-admin
We already have
$ matchpathcon /usr/sbin/start-ds-admin
/usr/sbin/start-ds-admin system_u:object_r:dirsrvadmin_exec_t:s0
in Fedora which needs to be back ported to RHEL.
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
https://rhn.redhat.com/errata/RHBA-2016-2283.html