Red Hat Bugzilla – Bug 1446777
SELinux prevents subscription manager from sending a D-bus message to puppet agent
Last modified: 2018-04-10 08:32:07 EDT
Description of problem: I'm attempting to use puppet to review and manage my subscriptions via subscription manager. Version-Release number of selected component (if applicable): subscription-manager-1.17.15-1.el7.x86_64 selinux-policy-targeted-3.13.1-102.el7_3.15.noarch How reproducible: 100% Steps to Reproduce: 1.run subscription manager commands via puppet 2. 3. Actual results: type=USER_AVC msg=audit(1493408550.286:153): pid=831 uid=81 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc: denied { send_msg } for msgtype=method_return dest=:1.68 spid=2647 tpid=2644 scontext=system_u:system_r:rhsmcertd_t:s0-s0:c0.c1023 tcontext=system_u:system_r:puppetagent_t:s0 tclass=dbus exe="/usr/bin/dbus-daemon" sauid=81 hostname=? addr=? terminal=?' Expected results: no errors Additional info: audit2allow suggests #============= rhsmcertd_t ============== allow rhsmcertd_t puppetagent_t:dbus send_msg;
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:0763