Bug 1359237 - AVC on dirsrv config caused by IPA installer
Summary: AVC on dirsrv config caused by IPA installer
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: ipa
Version: 7.3
Hardware: Unspecified
OS: Unspecified
Target Milestone: rc
: ---
Assignee: IPA Maintainers
QA Contact: Kaleem
Depends On:
TreeView+ depends on / blocked
Reported: 2016-07-22 14:57 UTC by Martin Babinsky
Modified: 2016-11-04 05:58 UTC (History)
3 users (show)

Fixed In Version: ipa-4.4.0-4.el7
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2016-11-04 05:58:57 UTC
Target Upstream Version:

Attachments (Terms of Use)
console output with verification steps (10.58 KB, text/plain)
2016-09-09 14:34 UTC, Kaleem
no flags Details

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2016:2404 0 normal SHIPPED_LIVE ipa bug fix and enhancement update 2016-11-03 13:56:18 UTC

Description Martin Babinsky 2016-07-22 14:57:18 UTC
This bug is created as a clone of upstream ticket:

IPA installer does not call 'restorecon' on '/etc/sysconfig/dirsrv' what is causing AVC and installation failed.

Jul 21 16:12:35 master.ipa.test audit[1]: AVC avc:  denied  { open } for  pid=1 comm="systemd" path="/etc/sysconfig/dirsrv" dev="vda1" ino=665018 scontext=system_u:system_r:init_t:s0 tcontext=unconfined_u:object
Jul 21 16:12:35 master.ipa.test systemd[1]: dirsrv@IPA-TEST.service: Failed to load environment files: Permission denied
Jul 21 16:12:35 master.ipa.test systemd[1]: dirsrv@IPA-TEST.service: Failed to run 'start' task: Permission denied
Jul 21 16:12:35 master.ipa.test systemd[1]: Failed to start 389 Directory Server IPA-TEST..


Reproducible on F24

Comment 2 Martin Bašti 2016-07-22 15:00:31 UTC
Steps to reproduce:
1. # setenforce 1
2. # ipa-server-install
3. installation will fail on restarting dirsrv

I was able to reproduce this locally on my local VM, but I haven't been able to to reproduce this in lab.

But anyway we should play safe and prevent possible future AVCs.

Comment 4 Kaleem 2016-09-09 14:33:10 UTC

IPA Version:
[root@dhcp207-129 ~]# rpm -q ipa-server
[root@dhcp207-129 ~]# 

Please find the attached console output.

Comment 6 Kaleem 2016-09-09 14:34:50 UTC
Created attachment 1199493 [details]
console output with verification steps

Comment 8 errata-xmlrpc 2016-11-04 05:58:57 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.