Bug 630112
Summary: | SELinux is preventing /usr/libexec/telepathy-haze from connecting to port 1533. | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Joel <hundred17> |
Component: | selinux-policy | Assignee: | Daniel Walsh <dwalsh> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | medium | Docs Contact: | |
Priority: | low | ||
Version: | 14 | CC: | domg444, dominick.grift, dwalsh, mgrepl, mildred-bug.redhat |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Linux | ||
Whiteboard: | setroubleshoot_trace_hash:10099399c175fd30c076ce1fbb97114ddffd630bf58ec55b3ca088e909840b27 | ||
Fixed In Version: | selinux-policy-3.9.3-1.fc14 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2010-09-11 03:43:02 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Joel
2010-09-03 18:02:39 UTC
Dominick should we add a port definition for this or put in jabber? In general i believe for the file transfer to work the client needs to connect to random ports (that is why the telepathy boolean is implemented) However: 1. I have not written policy for telepathy haze nor have i tried it. 2. This is what i found: Prior to Manager 2007 8.3 and Sametime 7.5.1, Sametime File Transfer was supported only by having Sametime IM clients connect on a port other than 1533. Starting with IM Manager 2007 8.3 and Sametime 7.5.1 IM Manager supports File Transfer connections on port 1533. 3. If the above is applicable here and if a connection to tcp 1533 is sufficient, then i would add a new port declaration for "sametime". That way we can have decent file transfer functionality for telepathy-haze. 4. It is my believe that we should declare as many port types as possible, and in this reasoning it would be best to add the sametime port declaration. So in short: The preferred method is to add a new port declaration for tcp:1533. Hopefully this will be sufficient to support this functionality. If however, besides connecting to tcp:1533, telepathy-haze needs to connect to other generic ports (some port range, or random ports), then it is encouraged to set the boolean that allows all telepathy_connection_managers to connect to all generic ports. http://publib.boulder.ibm.com/infocenter/sametime/v7r5m1/topic/com.ibm.help.sametime.admin.doc/st_adm_intro_whatstserver_c.html I think sametime is like msn, jabber etcetera and that the haze connection manager is used for this service/protocol. Thus i think we should declare a sametime_port_t for tcp:1533 Fixed in selinux-policy-3.9.3-1.fc14 selinux-policy-3.9.3-1.fc14 has been submitted as an update for Fedora 14. https://admin.fedoraproject.org/updates/selinux-policy-3.9.3-1.fc14 selinux-policy-3.9.3-1.fc14 has been pushed to the Fedora 14 testing repository. If problems still persist, please make note of it in this bug report. If you want to test the update, you can install it with su -c 'yum --enablerepo=updates-testing update selinux-policy'. You can provide feedback for this update here: https://admin.fedoraproject.org/updates/selinux-policy-3.9.3-1.fc14 Verified, I can now connect with the new selinux-policy-3.9.3-1.fc14.noarch. selinux-policy-3.9.3-1.fc14 has been pushed to the Fedora 14 stable repository. If problems still persist, please make note of it in this bug report. |