Bug 1402381

Summary: denied { connectto } comm="ods-signer" path="/run/opendnssec/engine.sock"
Product: [Fedora] Fedora Reporter: Petr Spacek <pspacek>
Component: selinux-policy-targetedAssignee: Lukas Vrabec <lvrabec>
Status: CLOSED ERRATA QA Contact: Ben Levenson <benl>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 25CC: dwalsh
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-04-25 02:23:33 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description Petr Spacek 2016-12-07 12:18:31 UTC
Description of problem:


Version-Release number of selected component (if applicable):


How reproducible:


Steps to Reproduce:
1. install FreeIPA DNS server packages:
$ dnf install freeipa-server-dns -y

2. install FreeIPA server:
ADMINPW=root4lab
DOMAIN=ipa.test.
$ ipa-server-install --ds-password="$ADMINPW" --admin-password="$ADMINPW" "--domain=ipa.test" "--realm=IPA.TEST" --unattended --setup-dns --auto-forwarders

3. install FreeIPA DNSSEC master:
$ ipa-dns-install --unattended --auto-forwarders --dnssec-master

4. enable DNSSEC for a zone:
$ echo root4lab | kinit admin
$ ipa dnszone-mod ipa.test --dnssec=1

Actual results:
$ journalctl -f
audit[2753]: AVC avc:  denied  { connectto } for  pid=2753 comm="ods-signer" path="/run/opendnssec/engine.sock" scontext=system_u:system_r:opendnssec_t:s0 tcontext=system_u:system_r:ipa_ods_exporter_t:s0 tclass=unix_stream_socket permissive=1


Expected results:
No AVC, it should work.

Additional info:
It seems that previous Fedora versions had the socket in /var/run but F25 has it in /run. Maybe this is the problem?

Comment 1 Fedora Update System 2017-04-19 20:36:06 UTC
selinux-policy-3.13.1-225.13.fc25 has been submitted as an update to Fedora 25. https://bodhi.fedoraproject.org/updates/FEDORA-2017-0af0456dcc

Comment 2 Fedora Update System 2017-04-20 18:24:54 UTC
selinux-policy-3.13.1-225.13.fc25 has been pushed to the Fedora 25 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-0af0456dcc

Comment 3 Fedora Update System 2017-04-25 02:23:33 UTC
selinux-policy-3.13.1-225.13.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.