Bug 784689

Summary: avc errors when installing ipa client
Product: Red Hat Enterprise Linux 6 Reporter: Namita Soman <nsoman>
Component: selinux-policyAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED NOTABUG QA Contact: BaseOS QE Security Team <qe-baseos-security>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 6.2CC: dwalsh, jgalipea, mmalik, rcritten, sgallagh
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-01-26 22:41:59 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Attachments:
Description Flags
avc log
none
sssd log
none
ipa client install log none

Description Namita Soman 2012-01-25 19:50:56 UTC
Description of problem:
When installing ipa-client, see message:
<snip>
...
SSSD enabled
Unable to find 'admin' user with 'getent passwd admin'!
Recognized configuration: SSSD
NTP enabled

...
<snip>

And avc errors are seen. Attaching log.
Also attaching log for sssd and ipaclient install

Version-Release number of selected component (if applicable):
selinux-policy-3.7.19-126.el6.noarch
sssd-1.5.1-66.el6.x86_64
ipa-client-2.1.3-9.el6.x86_64

How reproducible:
often

Steps to Reproduce:
1. Install ipaclient as admin:
ipa-client-install 
  
Actual results:
Seeing msg: Unable to find 'admin' user with 'getent passwd admin'!
and avc errors

Expected results:
install to complete with no avcs.

Additional info:

Comment 1 Namita Soman 2012-01-25 19:53:31 UTC
Created attachment 557509 [details]
avc log

Comment 2 Namita Soman 2012-01-25 19:54:11 UTC
Created attachment 557510 [details]
sssd log

Comment 3 Namita Soman 2012-01-25 19:54:41 UTC
Created attachment 557511 [details]
ipa client install log

Comment 5 Milos Malik 2012-01-26 08:20:38 UTC
/etc/resolv.conf is mislabelled. Please run following command as root:

restorecon -Rv /etc

Comment 6 Daniel Walsh 2012-01-26 22:41:59 UTC
Did resolv.conf get created in /dev/shm?  It looks like it was created on a tmpfs_t file system and then mv'd to /etc.