Bug 453410
Summary: | vpnc does not connect and generates error messages | ||||||||
---|---|---|---|---|---|---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | C. Y. Wong <wongc> | ||||||
Component: | vpnc | Assignee: | Tomas Mraz <tmraz> | ||||||
Status: | CLOSED CURRENTRELEASE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||||
Severity: | medium | Docs Contact: | |||||||
Priority: | low | ||||||||
Version: | 9 | CC: | mnowak, wtogami | ||||||
Target Milestone: | --- | ||||||||
Target Release: | --- | ||||||||
Hardware: | i386 | ||||||||
OS: | Linux | ||||||||
Whiteboard: | |||||||||
Fixed In Version: | Fedora 9 | Doc Type: | Bug Fix | ||||||
Doc Text: | Story Points: | --- | |||||||
Clone Of: | Environment: | ||||||||
Last Closed: | 2008-07-22 13:01:03 UTC | Type: | --- | ||||||
Regression: | --- | Mount Type: | --- | ||||||
Documentation: | --- | CRM: | |||||||
Verified Versions: | Category: | --- | |||||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
Cloudforms Team: | --- | Target Upstream Version: | |||||||
Embargoed: | |||||||||
Attachments: |
|
Description
C. Y. Wong
2008-06-30 13:46:13 UTC
Created attachment 310586 [details]
dump from 'ausearch -m AVC'
Unfortunately I don't see any related AVCs in the dump. Can you try cleaning up the /var/log/audit/audit.log file and run 'setenforce 0' and retry the vpnc connection? If that helps it is really SELinux related problem and has to be fixed in the policy. Dan, were there any recent changes related to vpnc or ip and ifconfig in SELinux policy? Thanks Tomas! I clean up /var/log/audit/audit.log and run /usr/sbin/setenforce 0 and then try the vpnc as suggested by Tomas. Now, the vpnc works and the connection gets to the intended destination as it should. So, it seems that this 'setenforce 0' works. Now, I guess we fix this 'SELinux related problem and has to be fixed in the policy'. C.Y. Wong Can you now attach the 'ausearch -m AVC' dump? Created attachment 310608 [details]
'ausearch -m AVC' dump
this is the 'ausearch -m AVC' dump attachment requested by tmraz.
at 2008-06-30 11:39 EST.
As I reported at 11:18 EST, the problem was rectified by doing 'setenforce 0'
and then vpnc. I can then get the vpnc connection to the destination as I
intended, with no error messages. But, I do not know whether you may like to
fix this problem in vpnc so that we do not need to do 'setenforce 0' every time
we use vpnc.
Thanks.
C. Y. Wong
The weird on this is that when I issued setenforce 0; vpnc; vpnc-disconnect; it worked and then setenforce 1; vpnc; vpnc-disconnect; it worked nice then too. Maybe behind this is only my lack of SELinux expertise and it's expected. I installed the latest bug-update (07/01/2008): selinux-policy-3.3.1.72.fc9(noarch) and selinuc-policy-targetd-3.3.1.72.fc9(noarch). [I also installed the latest kernel 2.6.25.9-76.fc9(i686). But the kernel version probably does not seem to matter.] I was able to connect by vpnc to the intended destination without error messages. It appears that this problem of "vpnc does not connect and gives error messages" has been fixed. This disappeared somehow, close it, then, somehow too. |