Bug 164377

Summary: SELinux blocks samba from accessing an AD password server
Product: [Fedora] Fedora Reporter: Danny Padwa <daniel.padwa>
Component: selinux-policy-targetedAssignee: Daniel Walsh <dwalsh>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 4   
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: 1.25.3-9 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-08-19 07:51:36 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
Fix selinux-policy-targeted to allow smbd_t to connect out to AD none

Description Danny Padwa 2005-07-27 14:16:00 UTC
Description of problem:
In one of Samba's modes, the samba server validates clients against an existing 
MSFT AD infrastructure.   To do this, it needs to be able to open a socket 
connection to the relevant service.   selinux-policy-targeted blocks this

Version-Release number of selected component (if applicable):
1.25.3

How reproducible:
Extremely

Steps to Reproduce:
1. Configure samba for "security = server"
2. Try to connect to it from a Windows machine
3.
  
Actual results:
It fails (very slowly).   Message in the AVC log about an inability to do a 
name_connect on port 139 or 445

Expected results:
It should work

Additional info:
Attached find a patch that fixes it

Comment 1 Danny Padwa 2005-07-27 14:16:00 UTC
Created attachment 117190 [details]
Fix selinux-policy-targeted to allow smbd_t to connect out to AD

Comment 2 Daniel Walsh 2005-07-28 16:45:50 UTC
Fixed in selinux-policy-targetd-1.25.3-9