Bug 1363662

Summary: avc: denied message during IPA replica install
Product: Red Hat Enterprise Linux 7 Reporter: Kaleem <ksiddiqu>
Component: selinux-policyAssignee: Lukas Vrabec <lvrabec>
Status: CLOSED ERRATA QA Contact: Stefan Kremen <skremen>
Severity: high Docs Contact:
Priority: high    
Version: 7.3CC: lvrabec, mgrepl, mmalik, nsoman, plautrba, pvoborni, pvrabec, skremen, ssekidde
Target Milestone: rcKeywords: Regression
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: selinux-policy-3.13.1-93.el7 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-11-04 02:35:55 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Kaleem 2016-08-03 10:02:27 UTC
Description of problem:

Following avc denial  seen during IPA replica install

[root@dhcp207-130 ~]# ausearch -m avc -ts today
----
time->Wed Aug  3 15:07:38 2016
type=PATH msg=audit(1470217058.429:1837): item=0 name="/usr/share/dirsrv/.k5identity" objtype=UNKNOWN
type=CWD msg=audit(1470217058.429:1837):  cwd="/"
type=SYSCALL msg=audit(1470217058.429:1837): arch=c000003e syscall=2 success=no exit=-2 a0=7f213400bf00 a1=0 a2=1b6 a3=24 items=1 ppid=1 pid=18634 auid=4294967295 uid=389 gid=389 euid=389 suid=389 fsuid=389 egid=389 sgid=389 fsgid=389 tty=(none) ses=4294967295 comm="ns-slapd" exe="/usr/sbin/ns-slapd" subj=system_u:system_r:dirsrv_t:s0 key=(null)
type=AVC msg=audit(1470217058.429:1837): avc:  denied  { search } for  pid=18634 comm="ns-slapd" name="dirsrv" dev="dm-0" ino=4945014 scontext=system_u:system_r:dirsrv_t:s0 tcontext=system_u:object_r:dirsrv_share_t:s0 tclass=dir
[root@dhcp207-130 ~]#

Version-Release number of selected component (if applicable):
[root@dhcp207-130 ~]# rpm -q ipa-server 389-ds-base selinux-policy
ipa-server-4.4.0-4.el7.x86_64
389-ds-base-1.3.5.10-5.el7.x86_64
selinux-policy-3.13.1-92.el7.noarch
[root@dhcp207-130 ~]#

How reproducible:
Always

Steps to Reproduce:
1. Install IPA master
2. Install IPA replica

Actual results:
AVC denial seen on replica

Expected results:
No AVC denial on replica

Additional info:

Comment 3 Lukas Vrabec 2016-08-05 12:58:57 UTC
We need to add allow rules for dirsrv policy.

Comment 9 errata-xmlrpc 2016-11-04 02:35:55 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2016-2283.html