Bug 172185
Summary: | Additional rules needed for postfix to run | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Chris Croome <chris> |
Component: | selinux-policy-targeted | Assignee: | Daniel Walsh <dwalsh> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 4 | ||
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | i386 | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2005-11-03 12:39:22 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Chris Croome
2005-11-01 10:05:18 UTC
file_t indicates that you have a very badly labeled file system. Perhaps you booted with selinux=0 or added a new disk, you need to relabel the machine you can do this with touch /.autorelabel reboot Hmm... I think this issue is caused by the encrypted partitions I have set up, /home/ and /etc/crypt/ (where the Postfix TLS key is) are manually mounted after booting (and postfix is manually started). These partitions have been set up using the Fedora cryptsetup-luks package. I did a relabel as suggested and after that I had to add these lines to postfix.te: allow postfix_master_t user_home_dir_t:dir search; allow postfix_smtpd_t default_t:dir getattr; And these to spamd.te before things started working properly again: allow spamd_t file_t:dir { getattr search }; allow spamd_t file_t:dir write; allow spamd_t file_t:file getattr; allow spamd_t file_t:dir add_name; allow spamd_t file_t:file create; allow spamd_t file_t:dir remove_name; allow spamd_t file_t:file write; allow spamd_t file_t:file { link unlink }; allow spamd_t file_t:file unlink; allow spamd_t file_t:file { ioctl read }; allow spamd_t file_t:file append; I guess this is just a side effect using using some crypted partitions...? |