Bug 141571
Summary: | named logs in /var/named are considered zone files, append denied | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Sven <rhbugzilla> |
Component: | selinux-policy-targeted | Assignee: | Daniel Walsh <dwalsh> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 3 | CC: | jvdias |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | i686 | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2004-12-08 17:08:37 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Sven
2004-12-02 06:33:29 UTC
It is designed so that those files should go into the data directory. Try channel named_lameservers_log { file "/var/named/data/named_lameservers.log" versions 3 size 5m; print-category yes; print-severity yes; print-time yes; }; yep, after reconfiguring and restarting, the new log files are now root:object_r:named_cache_t, and no complaints so far in syslog. when did this data subdirectory thing happen, because I don't remember seeing anything about it before..? It happened as a new version in FC3, as a security messure. Basically we want to prevent a compromized named from having the ability to modify the master files. I think a nice idea would be for the named service script ( /etc/init.d/named ), on startup to check if SELinux is enabled AND the named_write_master_zones boolean is enabled; if so, it will ensure that $ROOTDIR/var/named has the correct file system permissions to enable write by the named:named user, setting them to g+w if not. I'll try to get this into the next release of bind (bind-9.3.0-2 on FC4). Then all users would have to do to enable DDNS is enable the boolean with the GUI. |