Bug 149047 - SELinux Apache tutorial - describe the bug
Summary: SELinux Apache tutorial - describe the bug
Keywords:
Status: CLOSED CANTFIX
Alias: None
Product: Fedora Documentation
Classification: Retired
Component: selinux-apache
Version: devel
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Colin Walters
QA Contact: Tammy Fox
URL: http://fedora.redhat.com/docs/selinux...
Whiteboard: checkRelevance
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2005-02-18 07:41 UTC by Ben
Modified: 2018-04-11 08:25 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2008-09-08 12:23:50 UTC
Embargoed:


Attachments (Terms of Use)

Description Ben 2005-02-18 07:41:56 UTC
Description of problem:

The SELinux Apache FAQ gives a nice example of how to run CGIs as
different users on virtual hosts using suEXEC. Unfortunately, this
seems to cause problems with SELinux (I think with the logging?). If I
remove the SuexecUserGroup directive from the virtual hosts, my CGI
sample script works great. Put it back, and I get this:

blingbling kernel: audit(1108712168.806:0): avc:  denied  { write }
for  pid=5276 exe=/usr/sbin/suexec name=httpd dev=md0 ino=3260434
scontext=root:system_r:httpd_suexec_t
tcontext=system_u:object_r:httpd_log_t tclass=dir

[provide details, patches, etc.]

Document version:

selinux-apache-0.5-1 (2004-10-19-T21:24-0500)

Comment 1 Matěj Cepl 2008-09-05 19:34:00 UTC
Just a question from your friendly bugmaster -- is this bug still relevant or should it be closed as obsolete?

Comment 2 Ben 2008-09-06 01:07:25 UTC
I doubt it, but I'm not in a position to test, unfortunately.

Comment 3 Karsten Wade 2008-09-06 14:27:07 UTC
While I'm not fully positive the methodology in SELinux is different, I'm fairly certain it is by now.

The document referenced and version it came from are no longer maintained, it is effectively end-of-life.

Comment 4 Matěj Cepl 2008-09-08 12:23:50 UTC
OK, let's close it. If anybody objects, they can reopen it.


Note You need to log in before you can comment on or make changes to this bug.