Bug 801173
Summary: | SELinux is preventing /usr/lib64/dbus-1/dbus-daemon-launch-helper from 'connectto' accesses on the unix_stream_socket /var/lib/sss/pipes/nss. | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Stef Walter <stefw> |
Component: | selinux-policy | Assignee: | Miroslav Grepl <mgrepl> |
Status: | CLOSED NOTABUG | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | unspecified | Docs Contact: | |
Priority: | unspecified | ||
Version: | 17 | CC: | dominick.grift, dwalsh, mgrepl, sbonazzo, vondruch |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Unspecified | ||
Whiteboard: | abrt_hash:4ce084f9863055131b9a23751cbc20ba2cdcdccd3db915200af7463a99a86d94 | ||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2012-03-08 09:32:01 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Stef Walter
2012-03-07 20:38:12 UTC
This tells us you started sssd by hand ... I mean without using the sssd unit file. So what happened: unconfined_t @ sssd_exec_t -> sssd running as unconfined_t $ systemctl restart sssd.service I'm working on sssd. Any ideas on how would i start it manually, while respecting selinux restrictions? Start it with the service script. If you want to run it from a debugger, you could connect to the running daemon, or put the machine in permissive mode and ignore the AVC's If you need to start it with "-d" option there is a way and you can use runcon. $ runcon -u system_u -r system_r -t initrc_t -- runcon -t sssd_t -- /sbin/sssd -d LEVEL Thanks! *** Bug 963533 has been marked as a duplicate of this bug. *** |