Bug 1983308
Summary: | SELinux Blocking Postfix+PostgreSQL | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 8 | Reporter: | Joseph D. Wagner <joe> |
Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> |
Status: | CLOSED ERRATA | QA Contact: | Milos Malik <mmalik> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | CentOS Stream | CC: | bstinson, jwboyer, lvrabec, mmalik, pkoncity, plautrba, zpytela |
Target Milestone: | beta | Keywords: | Triaged |
Target Release: | 8.8 | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | selinux-policy-3.14.3-112.el8 | Doc Type: | No Doc Update |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2023-05-16 09:03:44 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Deadline: | 2022-08-16 |
Description
Joseph D. Wagner
2021-07-17 14:23:35 UTC
Hi Joseph,
I have a few questions. I'm stucked in reproducing this bug,
> 9. psql -d vmaildb -U vmailuser
when I try to connect vmaildb to vmailuser in database it appear only error "psql: FATAL: Peer authentication failed for user "vmailuser"
" and I'm not to able continue in other steps. Any clue where can be a issue?
Also can you pleas show me a label of /etc/postfix/pgsql/virtual_mailbox_maps.cf ?
$ ls -Z /etc/postfix/pgsql/virtual_mailbox_maps.cf
Thanks,
Patrik
1) You'll need to change the METHOD entry in /var/lib/pgsql/data/pg_hba.conf from "peer" to something like "trust", "md5", or "scram-sha-256". Be sure to setup the postgres account first (unless you go with "trust"), because postgres is the admin one. 2) -rw-r-----. 1 root postfix system_u:object_r:postfix_etc_t:s0 288 Jul 26 2021 /etc/postfix/pgsql/virtual_mailbox_maps.cf This commit is needed: commit 3dd03dad6dfc3d5b07fbd31eec2cbceabfdfd844 (HEAD -> rawhide, upstream/rawhide) Author: Zdenek Pytela <zpytela> Date: Fri Nov 25 19:11:50 2022 +0100 Allow postfix/smtpd read kerberos key table Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (selinux-policy bug fix and enhancement update), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2023:2965 |