Bug 1938216

Summary: Cannot use the graphical user interface when pam_tty_audit.so is enabled [rhel-8.3.0.z]
Product: Red Hat Enterprise Linux 8 Reporter: RHEL Program Management Team <pgm-rhel-tools>
Component: selinux-policyAssignee: Zdenek Pytela <zpytela>
Status: CLOSED ERRATA QA Contact: Milos Malik <mmalik>
Severity: urgent Docs Contact:
Priority: urgent    
Version: 8.3CC: abuckner, fkrska, kmoriguc, leonfauster, lvrabec, mmalik, plautrba, ssekidde, zpytela
Target Milestone: rcKeywords: AutoVerified, Triaged, ZStream
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Cause: When the pam_tty_audit pam module is enabled for a user session, systemd needs the audit_control capability to be able to control kernel audit configuration and rules. This capability was not allowed, Consequence: The systemd user manager fails to start, errors are logged and AVC denials audited. Graphical display managers do not work any longer as they use a systemd user session to spawn the greeter. Fix: The capability was added to the policy conditionally: it is required to turn on the new init_audit_control boolean which is off by default. Result: Uses can use the graphical user interface.
Story Points: ---
Clone Of: 1861771 Environment:
Last Closed: 2021-04-06 14:19:25 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1861771, 1962252    
Bug Blocks:    

Comment 14 errata-xmlrpc 2021-04-06 14:19:25 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (selinux-policy bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2021:1098