Bug 163091

Summary: vsftpd can't read cert_t files/directories
Product: [Fedora] Fedora Reporter: Bojan Smojver <bojan>
Component: selinux-policy-targetedAssignee: Daniel Walsh <dwalsh>
Status: CLOSED NEXTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 4   
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-07-15 11:55:02 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Bojan Smojver 2005-07-12 20:11:57 UTC
Description of problem:

This is a continuation of the cert_t problem, but instead of dovecot, the
culprit is now vsftpd. As an aside, I think I've seen bind do a similar thing at
one stage (with the policy file from July 9), but I'll have to fiddle with it to
verify...

Version-Release number of selected component (if applicable):
1.25.1-7

How reproducible:
Always.

Additional info:

Jul 12 17:51:23 beauty kernel: audit(1121154683.985:225): avc:  denied  { search
 } for  pid=26291 comm="vsftpd" name="pki" dev=dm-0 ino=481589 scontext=root:sys
tem_r:ftpd_t tcontext=system_u:object_r:cert_t tclass=dir
Jul 12 17:51:23 beauty kernel: audit(1121154683.989:226): avc:  denied  { search
 } for  pid=26291 comm="vsftpd" name="pki" dev=dm-0 ino=481589 scontext=root:sys
tem_r:ftpd_t tcontext=system_u:object_r:cert_t tclass=dir

Comment 1 Daniel Walsh 2005-07-14 15:28:34 UTC
selinux-policy-targeted-1.25.2-4

Comment 2 Bojan Smojver 2005-07-14 20:04:27 UTC
Where can I find that one? The testing repository goes up to -3.

Comment 3 Daniel Walsh 2005-07-14 20:31:02 UTC
It should be going out tonight.  You can grab a copy off of

ftp://people.redhat.com/dwalsh/SELinux/FC4


Comment 4 Bojan Smojver 2005-07-15 11:55:02 UTC
Looking good! I'll close for now.