Bug 1624289 - AVC denials noticed during test execution for SUB-CA test-suite in FIPS mode
Summary: AVC denials noticed during test execution for SUB-CA test-suite in FIPS mode
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: selinux-policy
Version: 7.5
Hardware: Unspecified
OS: Linux
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: Lukas Vrabec
QA Contact: Milos Malik
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-08-31 07:39 UTC by Nikhil Dehadrai
Modified: 2018-10-30 10:10 UTC (History)
11 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-10-30 10:09:38 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2018:3111 None None None 2018-10-30 10:10:13 UTC

Description Nikhil Dehadrai 2018-08-31 07:39:05 UTC
Description of problem:
AVC denials noticed during test execution for SUB-CA test-suite in FIPS mode

Version-Release number of selected component (if applicable):
selinux-policy-3.13.1-192.el7_5.6.noarch

How reproducible:
Always

Steps to Reproduce:
1. Execute test suite for SUB-CA in FIPS mode


Actual results:
AVC denials observed

Info: Searching AVC errors produced since 1535628416.69 (Thu Aug 30 16:56:56 2018)
Searching logs...
Running '/usr/bin/env LC_ALL=en_US.UTF-8 /sbin/ausearch -m AVC -m USER_AVC -m SELINUX_ERR -ts 08/30/2018 16:56:56 < /dev/null >/mnt/testarea/tmp.rhts-db-submit-result.I_AMPi 2>&1'
----
time->Thu Aug 30 17:08:10 2018
type=USER_AVC msg=audit(1535629090.430:449): pid=1036 uid=81 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc:  received policyload notice (seqno=4)  exe="/usr/bin/dbus-daemon" sauid=81 hostname=? addr=? terminal=?'
----
time->Thu Aug 30 17:08:13 2018
type=USER_AVC msg=audit(1535629093.007:450): pid=1036 uid=81 auid=4294967295 ses=4294967295 subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc:  received policyload notice (seqno=5)  exe="/usr/bin/dbus-daemon" sauid=81 hostname=? addr=? terminal=?'
----
time->Thu Aug 30 17:08:13 2018
type=USER_AVC msg=audit(1535629093.252:452): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='avc:  received policyload notice (seqno=4)  exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?'
----
time->Thu Aug 30 17:08:13 2018
type=USER_AVC msg=audit(1535629093.252:453): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='avc:  received policyload notice (seqno=5)  exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?'
----
time->Thu Aug 30 17:20:56 2018
type=PROCTITLE msg=audit(1535629856.837:535): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612031663261326535382D343831312D346264332D386434372D64623635623864356566626600766D2D69646D2D303136
type=SYSCALL msg=audit(1535629856.837:535): arch=c000003e syscall=88 success=no exit=-13 a0=1503824 a1=1a72d60 a2=0 a3=7f9f64e251f9 items=0 ppid=31388 pid=3367 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629856.837:535): avc:  denied  { create } for  pid=3367 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:21:04 2018
type=PROCTITLE msg=audit(1535629864.290:536): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612066396430333738362D366336372D343038382D386336662D31363336636162306231616200766D2D69646D2D303136
type=SYSCALL msg=audit(1535629864.290:536): arch=c000003e syscall=88 success=no exit=-13 a0=2e78844 a1=33e7c40 a2=0 a3=7f272d2b61f9 items=0 ppid=31388 pid=3428 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629864.290:536): avc:  denied  { create } for  pid=3428 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:21:09 2018
type=PROCTITLE msg=audit(1535629869.086:537): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612036323933373763652D616335632D343534312D393734652D66393337313833636336333400766D2D69646D2D303136
type=SYSCALL msg=audit(1535629869.086:537): arch=c000003e syscall=88 success=no exit=-13 a0=1fea914 a1=2559da0 a2=0 a3=7f47c5c5b1f9 items=0 ppid=31388 pid=3478 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629869.086:537): avc:  denied  { create } for  pid=3478 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:21:17 2018
type=PROCTITLE msg=audit(1535629877.419:539): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612066396430333738362D366336372D343038382D386336662D31363336636162306231616200766D2D69646D2D303136
type=SYSCALL msg=audit(1535629877.419:539): arch=c000003e syscall=88 success=no exit=-13 a0=2b06804 a1=3075b70 a2=0 a3=7fd6dc72c1f9 items=0 ppid=31388 pid=3579 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629877.419:539): avc:  denied  { create } for  pid=3579 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:21:16 2018
type=PROCTITLE msg=audit(1535629876.447:538): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612033323739393337352D643464632D343630642D396338372D36396231333431393735376400766D2D69646D2D303136
type=SYSCALL msg=audit(1535629876.447:538): arch=c000003e syscall=88 success=no exit=-13 a0=244b844 a1=29bac40 a2=0 a3=7fc6d5b821f9 items=0 ppid=31388 pid=3562 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629876.447:538): avc:  denied  { create } for  pid=3562 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:21:25 2018
type=PROCTITLE msg=audit(1535629885.352:540): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612033383865633138342D663337392D346232322D613838312D38616237353939646462323500766D2D69646D2D303136
type=SYSCALL msg=audit(1535629885.352:540): arch=c000003e syscall=88 success=no exit=-13 a0=1baf864 a1=211ec80 a2=0 a3=7f16326cc1f9 items=0 ppid=31388 pid=3647 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629885.352:540): avc:  denied  { create } for  pid=3647 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:21:36 2018
type=PROCTITLE msg=audit(1535629896.497:541): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612066396430333738362D366336372D343038382D386336662D31363336636162306231616200766D2D69646D2D303136
type=SYSCALL msg=audit(1535629896.497:541): arch=c000003e syscall=88 success=no exit=-13 a0=20c4824 a1=2633c20 a2=0 a3=7fdb451131f9 items=0 ppid=31388 pid=3745 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629896.497:541): avc:  denied  { create } for  pid=3745 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:21:57 2018
type=PROCTITLE msg=audit(1535629917.532:566): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612066643662353166342D386265632D343262652D386436642D66306137663064343864636200766D2D69646D2D303136
type=SYSCALL msg=audit(1535629917.532:566): arch=c000003e syscall=88 success=no exit=-13 a0=232b844 a1=289ac40 a2=0 a3=7f08e45611f9 items=0 ppid=31388 pid=3954 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629917.532:566): avc:  denied  { create } for  pid=3954 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:22:01 2018
type=PROCTITLE msg=audit(1535629921.520:578): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612066396430333738362D366336372D343038382D386336662D31363336636162306231616200766D2D69646D2D303136
type=SYSCALL msg=audit(1535629921.520:578): arch=c000003e syscall=88 success=no exit=-13 a0=1c32914 a1=21a1da0 a2=0 a3=7f842ed321f9 items=0 ppid=31388 pid=4001 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629921.520:578): avc:  denied  { create } for  pid=4001 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:22:36 2018
type=PROCTITLE msg=audit(1535629956.879:610): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612063666237633764662D393333652D346235382D616665362D63316262343061333735653600766D2D69646D2D303136
type=SYSCALL msg=audit(1535629956.879:610): arch=c000003e syscall=88 success=no exit=-13 a0=17e8914 a1=1d57da0 a2=0 a3=7f9a02d351f9 items=0 ppid=31388 pid=4369 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629956.879:610): avc:  denied  { create } for  pid=4369 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:22:37 2018
type=PROCTITLE msg=audit(1535629957.588:611): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612066396430333738362D366336372D343038382D386336662D31363336636162306231616200766D2D69646D2D303136
type=SYSCALL msg=audit(1535629957.588:611): arch=c000003e syscall=88 success=no exit=-13 a0=2690914 a1=2bffda0 a2=0 a3=7f19e4bde1f9 items=0 ppid=31388 pid=4382 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629957.588:611): avc:  denied  { create } for  pid=4382 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:22:46 2018
type=PROCTITLE msg=audit(1535629966.991:612): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612038353937623730612D316262392D343435302D383637322D30343533306334643038623600766D2D69646D2D303136
type=SYSCALL msg=audit(1535629966.991:612): arch=c000003e syscall=88 success=no exit=-13 a0=1dda8b4 a1=2349cf0 a2=0 a3=7f7480f561f9 items=0 ppid=31388 pid=4467 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629966.991:612): avc:  denied  { create } for  pid=4467 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:22:53 2018
type=PROCTITLE msg=audit(1535629973.498:613): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612032326361636436372D663161352D343765372D623431652D30376534333739393837616600766D2D69646D2D303136
type=SYSCALL msg=audit(1535629973.498:613): arch=c000003e syscall=88 success=no exit=-13 a0=1d22844 a1=2291c40 a2=0 a3=7efeef44f1f9 items=0 ppid=31388 pid=4529 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629973.498:613): avc:  denied  { create } for  pid=4529 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:08 2018
type=PROCTITLE msg=audit(1535629988.279:615): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612032373233616231342D346233352D346636312D613562382D35323963323935316239396100766D2D69646D2D303136
type=SYSCALL msg=audit(1535629988.279:615): arch=c000003e syscall=88 success=no exit=-13 a0=2d6d8b4 a1=32dccf0 a2=0 a3=7f8b3d94c1f9 items=0 ppid=31388 pid=4672 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629988.279:615): avc:  denied  { create } for  pid=4672 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:06 2018
type=PROCTITLE msg=audit(1535629986.023:614): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612061333762616636622D643762642D343137302D613464332D35636538383462303165333700766D2D69646D2D303136
type=SYSCALL msg=audit(1535629986.023:614): arch=c000003e syscall=88 success=no exit=-13 a0=2c77914 a1=31e6da0 a2=0 a3=7f6d6f97c1f9 items=0 ppid=31388 pid=4646 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629986.023:614): avc:  denied  { create } for  pid=4646 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:11 2018
type=PROCTITLE msg=audit(1535629991.719:616): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612037363561363866382D353064632D343534342D623461662D34363263333236313033343200766D2D69646D2D303136
type=SYSCALL msg=audit(1535629991.719:616): arch=c000003e syscall=88 success=no exit=-13 a0=1449914 a1=19b8da0 a2=0 a3=7f45c2f601f9 items=0 ppid=31388 pid=4716 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629991.719:616): avc:  denied  { create } for  pid=4716 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:14 2018
type=PROCTITLE msg=audit(1535629994.493:617): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612064633234656233312D616239322D343165652D623232322D64623934346339366261653800766D2D69646D2D303136
type=SYSCALL msg=audit(1535629994.493:617): arch=c000003e syscall=88 success=no exit=-13 a0=2b7c844 a1=30ebc40 a2=0 a3=7f63ec8b71f9 items=0 ppid=31388 pid=4744 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535629994.493:617): avc:  denied  { create } for  pid=4744 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:20 2018
type=PROCTITLE msg=audit(1535630000.215:618): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612032636133343438322D383031332D343239332D396163622D34626631643464333665653400766D2D69646D2D303136
type=SYSCALL msg=audit(1535630000.215:618): arch=c000003e syscall=88 success=no exit=-13 a0=1e218a4 a1=2390cc0 a2=0 a3=7f0c676571f9 items=0 ppid=31388 pid=4804 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630000.215:618): avc:  denied  { create } for  pid=4804 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:23 2018
type=PROCTITLE msg=audit(1535630003.797:619): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612035316166336261332D663238662D346237612D623061362D34303765613431373365326600766D2D69646D2D303136
type=SYSCALL msg=audit(1535630003.797:619): arch=c000003e syscall=88 success=no exit=-13 a0=1c00844 a1=216fc40 a2=0 a3=7f91bb6601f9 items=0 ppid=31388 pid=4858 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630003.797:619): avc:  denied  { create } for  pid=4858 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:25 2018
type=PROCTITLE msg=audit(1535630005.909:620): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612066313433663263322D363837332D346166362D393730382D64663435666566313931386600766D2D69646D2D303136
type=SYSCALL msg=audit(1535630005.909:620): arch=c000003e syscall=88 success=no exit=-13 a0=16d8914 a1=1c47da0 a2=0 a3=7fa37f3cc1f9 items=0 ppid=31388 pid=4884 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630005.909:620): avc:  denied  { create } for  pid=4884 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:29 2018
type=PROCTITLE msg=audit(1535630009.653:621): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612031303236613531342D356261362D346531312D623035392D38646463326464636339326100766D2D69646D2D303136
type=SYSCALL msg=audit(1535630009.653:621): arch=c000003e syscall=88 success=no exit=-13 a0=133b8b4 a1=18aacf0 a2=0 a3=7f152b61b1f9 items=0 ppid=31388 pid=4920 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630009.653:621): avc:  denied  { create } for  pid=4920 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:31 2018
type=PROCTITLE msg=audit(1535630011.505:622): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612037636131313466322D623362322D346166652D383734652D65343162656661363931333900766D2D69646D2D303136
type=SYSCALL msg=audit(1535630011.505:622): arch=c000003e syscall=88 success=no exit=-13 a0=251f914 a1=2a8eda0 a2=0 a3=7f501bf741f9 items=0 ppid=31388 pid=4947 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630011.505:622): avc:  denied  { create } for  pid=4947 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:32 2018
type=PROCTITLE msg=audit(1535630012.466:623): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612066396430333738362D366336372D343038382D386336662D31363336636162306231616200766D2D69646D2D303136
type=SYSCALL msg=audit(1535630012.466:623): arch=c000003e syscall=88 success=no exit=-13 a0=26c98d4 a1=2c38d60 a2=0 a3=7f5c684c41f9 items=0 ppid=31388 pid=4962 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630012.466:623): avc:  denied  { create } for  pid=4962 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:36 2018
type=PROCTITLE msg=audit(1535630016.164:624): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612061633231666636372D393662372D343935622D626538362D62636636333739346535666600766D2D69646D2D303136
type=SYSCALL msg=audit(1535630016.164:624): arch=c000003e syscall=88 success=no exit=-13 a0=1da6ac4 a1=2315d60 a2=0 a3=7faa806a41f9 items=0 ppid=31388 pid=5000 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630016.164:624): avc:  denied  { create } for  pid=5000 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:39 2018
type=PROCTITLE msg=audit(1535630019.022:625): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612034346132313764302D656537322D346164302D626439302D62313637313138653562616200766D2D69646D2D303136
type=SYSCALL msg=audit(1535630019.022:625): arch=c000003e syscall=88 success=no exit=-13 a0=27ee804 a1=2d5db70 a2=0 a3=7f925bc641f9 items=0 ppid=31388 pid=5035 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630019.022:625): avc:  denied  { create } for  pid=5035 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:44 2018
type=PROCTITLE msg=audit(1535630024.079:626): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612037393562313965302D613237612D346637642D383834312D35653134656134323266356300766D2D69646D2D303136
type=SYSCALL msg=audit(1535630024.079:626): arch=c000003e syscall=88 success=no exit=-13 a0=21e9914 a1=2758da0 a2=0 a3=7f39858791f9 items=0 ppid=31388 pid=5087 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630024.079:626): avc:  denied  { create } for  pid=5087 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:47 2018
type=PROCTITLE msg=audit(1535630027.972:627): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612033356166386163372D373365382D343565362D613530662D32356361306632636363303100766D2D69646D2D303136
type=SYSCALL msg=audit(1535630027.972:627): arch=c000003e syscall=88 success=no exit=-13 a0=15db914 a1=1b4ada0 a2=0 a3=7fbdea1c11f9 items=0 ppid=31388 pid=5140 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630027.972:627): avc:  denied  { create } for  pid=5140 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:49 2018
type=PROCTITLE msg=audit(1535630029.854:628): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612066666437303931392D623537622D346333352D383464342D32363838386335323166613800766D2D69646D2D303136
type=SYSCALL msg=audit(1535630029.854:628): arch=c000003e syscall=88 success=no exit=-13 a0=1f4e884 a1=24bdca0 a2=0 a3=7f98dedf11f9 items=0 ppid=31388 pid=5166 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630029.854:628): avc:  denied  { create } for  pid=5166 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:55 2018
type=PROCTITLE msg=audit(1535630035.946:630): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612035376233653762652D623433632D346361382D623930332D39323561633439643434623100766D2D69646D2D303136
type=SYSCALL msg=audit(1535630035.946:630): arch=c000003e syscall=88 success=no exit=-13 a0=187bac4 a1=1dead60 a2=0 a3=7f1be03bc1f9 items=0 ppid=31388 pid=5228 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630035.946:630): avc:  denied  { create } for  pid=5228 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:53 2018
type=PROCTITLE msg=audit(1535630033.799:629): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612037366561393861642D613363332D343533322D393037342D39666265316564323838623700766D2D69646D2D303136
type=SYSCALL msg=audit(1535630033.799:629): arch=c000003e syscall=88 success=no exit=-13 a0=29178f4 a1=2e86d80 a2=0 a3=7f0f42ab51f9 items=0 ppid=31388 pid=5202 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630033.799:629): avc:  denied  { create } for  pid=5202 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:23:59 2018
type=PROCTITLE msg=audit(1535630039.451:631): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612035333864363331612D633436632D343232382D623761612D39386135323366666566323600766D2D69646D2D303136
type=SYSCALL msg=audit(1535630039.451:631): arch=c000003e syscall=88 success=no exit=-13 a0=284a8d4 a1=2db9d60 a2=0 a3=7f32927ec1f9 items=0 ppid=31388 pid=5272 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630039.451:631): avc:  denied  { create } for  pid=5272 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:24:02 2018
type=PROCTITLE msg=audit(1535630042.262:632): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612061353534333039332D666264342D346261322D613930632D32633232303263356337303300766D2D69646D2D303136
type=SYSCALL msg=audit(1535630042.262:632): arch=c000003e syscall=88 success=no exit=-13 a0=1e05804 a1=2374b70 a2=0 a3=7fcd5ae401f9 items=0 ppid=31388 pid=5298 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630042.262:632): avc:  denied  { create } for  pid=5298 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:24:05 2018
type=PROCTITLE msg=audit(1535630045.418:633): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612036623135346462662D363637342D343132382D386161382D39396634373963656438343800766D2D69646D2D303136
type=SYSCALL msg=audit(1535630045.418:633): arch=c000003e syscall=88 success=no exit=-13 a0=14a1fd4 a1=1a10bd0 a2=0 a3=7f6ede6a91f9 items=0 ppid=31388 pid=5333 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630045.418:633): avc:  denied  { create } for  pid=5333 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:24:53 2018
type=PROCTITLE msg=audit(1535630093.032:747): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612066396430333738362D366336372D343038382D386336662D31363336636162306231616200766D2D69646D2D303136
type=SYSCALL msg=audit(1535630093.032:747): arch=c000003e syscall=88 success=no exit=-13 a0=19a5b94 a1=1f15080 a2=0 a3=7f5e699a81f9 items=0 ppid=31388 pid=6132 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630093.032:747): avc:  denied  { create } for  pid=6132 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
----
time->Thu Aug 30 17:25:45 2018
type=PROCTITLE msg=audit(1535630145.642:851): proctitle=2F7573722F62696E2F707974686F6E32002F7573722F6C6962657865632F6970612F6970612D706B692D72657472696576652D6B65790063615369676E696E674365727420636572742D706B692D63612061663039336661352D373237382D346132372D616436642D32643336666135653861333100766D2D69646D2D303136
type=SYSCALL msg=audit(1535630145.642:851): arch=c000003e syscall=88 success=no exit=-13 a0=15388f4 a1=1aa7d80 a2=0 a3=7fd6fc09f1f9 items=0 ppid=31388 pid=7074 auid=4294967295 uid=17 gid=17 euid=17 suid=17 fsuid=17 egid=17 sgid=17 fsgid=17 tty=(none) ses=4294967295 comm="ipa-pki-retriev" exe="/usr/bin/python2.7" subj=system_u:system_r:tomcat_t:s0 key=(null)
type=AVC msg=audit(1535630145.642:851): avc:  denied  { create } for  pid=7074 comm="ipa-pki-retriev" name="47298331.0" scontext=system_u:system_r:tomcat_t:s0 tcontext=system_u:object_r:tomcat_tmp_t:s0 tclass=lnk_file
Fail: AVC messages found.
Checking for errors...
Using stronger AVC checks.
	Define empty RHTS_OPTION_STRONGER_AVC parameter if this causes any problems.
Running 'cat /mnt/testarea/tmp.rhts-db-submit-result.I_AMPi | /sbin/ausearch -m AVC -m SELINUX_ERR'
Fail: AVC messages found.
Running 'cat %s | /sbin/ausearch -m USER_AVC >/mnt/testarea/tmp.rhts-db-submit-result.AlvCWh 2>&1'
Info: No AVC messages found.
/bin/grep 'avc: ' /mnt/testarea/dmesg.log | /bin/grep --invert-match TESTOUT.log
No AVC messages found in dmesg
Running '/usr/sbin/sestatus'
SELinux status:                 enabled
SELinuxfs mount:                /sys/fs/selinux
SELinux root directory:         /etc/selinux
Loaded policy name:             targeted
Current mode:                   enforcing
Mode from config file:          enforcing
Policy MLS status:              enabled
Policy deny_unknown status:     allowed
Max kernel policy version:      31
Running 'rpm -q selinux-policy || true'
selinux-policy-3.13.1-192.el7_5.6.noarch

Expected results:
No AVC messages should be observed

Additional info:
AVC denials are observed for both MASTER / REPLICA test executions.

Comment 2 msiddiqu 2018-08-31 11:50:16 UTC
Similar AVC errors are observed for "IPA Upgrade from RHEL-7.5-Update-0.0 to 7.5.4" 

Version-Release number of selected component (if applicable):
selinux-policy-3.13.1-192.el7_5.6.noarch
selinux-policy-3.13.1-192.el7_5.3.noarch

MASTER:
Setup-subca-on-Master: selinux-policy-3.13.1-192.el7_5.3.noarch
Check-subca-on-Master-after-upgrade/avc : selinux-policy-3.13.1-192.el7_5.6.noarch
Setup-Trust-From-MASTER-with-AD : selinux-policy-3.13.1-192.el7_5.3.noarch
IPA-server-doesnot-report-httpd-avc-denials-after-upgrade-bz1164896 : selinux-policy-3.13.1-192.el7_5.3.noarch

REPLICA: 
IPA-server-doesnot-report-httpd-avc-denials-after-upgrade-bz1164896/avc : selinux-policy-3.13.1-192.el7_5.6.noarch
IPA-server-doesnot-report-httpd-avc-denials-after-upgrade-bz1164896/avc : selinux-policy-3.13.1-192.el7_5.3.noarch

Comment 12 errata-xmlrpc 2018-10-30 10:09:38 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2018:3111


Note You need to log in before you can comment on or make changes to this bug.