Bug 1039851 - [selinux policy] Zabbix agent monitoring access denied
Summary: [selinux policy] Zabbix agent monitoring access denied
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: selinux-policy
Version: 6.5
Hardware: x86_64
OS: Linux
urgent
urgent
Target Milestone: rc
: ---
Assignee: Miroslav Grepl
QA Contact: Milos Malik
URL:
Whiteboard:
Depends On: 1032691 1038237
Blocks: 1034076
TreeView+ depends on / blocked
 
Reported: 2013-12-10 07:44 UTC by Miroslav Grepl
Modified: 2018-12-09 17:21 UTC (History)
18 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of: 1032691
Environment:
Last Closed: 2014-10-14 07:58:25 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2014:1568 0 normal SHIPPED_LIVE selinux-policy bug fix and enhancement update 2014-10-14 01:27:37 UTC

Comment 3 Volker Fröhlich 2014-03-31 08:37:32 UTC
Do you happen to know when this update is going to ship?

Comment 4 Daniel Walsh 2014-03-31 20:07:01 UTC
It will ship with the RHEL6.6 update.  If you want to try it now, you can grab the latest selinux-policy package for RHEL6 from

http://people.redhat.com/~dwalsh/SELinux/RHEL6

Comment 7 Dan Ham 2014-08-21 10:09:40 UTC
I have installed the latest policy (3.7.19-251) with Zabbix 2.2.5-1. The Zabbix source rpm was taken from fc21 and repackaged for el6 - I pretty much followed/implemented the changes applied to the Zabbix22 package available from EPEL with a few minor differences. 

This seems to resolve all the problems I was previously getting with the denials for the agent. However, I did get one denial for the server:

type=AVC msg=audit(1408552583.666:87): avc:  denied  { read } for  pid=1504 comm="zabbix_server" name="zabbix_server.log" dev=dm-2 ino=524322 scontext=system_u:system_r:zabbix_t:s0 tcontext=unconfined_u:object_r:var_log_t:s0 tclass=file

This was resolved with the following:

semanage fcontext -a -t zabbix_log_t "/var/log/zabbixsrv(/.*)?"
restorecon -Rv /var/log/zabbixsrv

Looks like the rule for labelling the 'new/separate' server log directory and files needs to be added to the policy.

Many Thanks,

Dan H

Comment 8 errata-xmlrpc 2014-10-14 07:58:25 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2014-1568.html


Note You need to log in before you can comment on or make changes to this bug.